topk-js@0.12.0
Malicious code in topk-js (npm)
Analysis
topk-js@0.12.0 is a trojanized NAPI-RS native binding package. The package itself contains only standard NAPI-RS JavaScript loader code, but its optional dependencies include platform-specific native .node binary packages (topk-js-win32-arm64-msvc, topk-js-win32-ia32-msvc, topk-js-win32-x64-msvc) that are known malware. When the package is required in a Node.js application, the loader resolves and loads the malicious native binary for the target platform, executing the embedded payload. The package has no repository, no lifecycle hooks, and the malicious behaviour is delivered through the native binary rather than JavaScript.
- analyzed by
- Leitwacht
- first seen
- Jul 20, 2026, 03:32 PM
- analyzed
- Jul 20, 2026, 03:33 PM
- weekly installs
- 73
Related advisories
- json-validator-utils@1.0.1
- habingeer@2.1.6
- tailwind-animationfound@2.3.7
- ts-vitest@1.1.1
- n8n-nodes-probe@1.0.0
- n8n-nodes-api-finder@1.0.0
- n8n-nodes-utils-helper@1.0.0
- chai-as-inspired@2.2.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.