isite@2026.7.2
Malicious code in isite (npm)
Analysis
isite@2026.7.2 is a trojanized version of a legitimate Node.js web framework. When required, the package POSTs its full configuration (including security keys, MongoDB connection details, session secrets, and proxy settings) to social-browser[.]com/api/core-trusted-data. The C2 server can respond with a "delete" command that triggers recursive deletion of the filesystem. The implant uses a custom obfuscation scheme (base64→number-pair encoding) to hide the C2 URL and activation logic, and is time-gated via encoded date values. The exfiltration uses HTTP POST with User-Agent "eval" to social-browser[.]com on port 80.
- analyzed by
- Leitwacht
- first seen
- Jul 16, 2026, 08:25 PM
- analyzed
- Jul 16, 2026, 08:42 PM
- weekly installs
- 16,799
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.