1239i32049i@0.1.0
Malicious code in 1239i32049i (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
The package runs a postinstall hook that fetches a base64-encoded payload from hxxps://dropper-crm[.]vercel[.]app/api/payload/ (parameterized by the environment variable P) and executes it as arbitrary JavaScript via new Function('require', ...). This is a remote code execution dropper — the published package is a small bootstrap that downloads and runs a second-stage payload from an attacker-controlled Vercel endpoint.
- analyzed by
- Leitwacht
- first seen
- Jul 21, 2026, 03:43 PM
- analyzed
- Jul 21, 2026, 03:43 PM
Related advisories
- faust-cont@1.0.0
- quickbuf@1.0.1
- consumerweb-calurls@99.9.1
- consumerweb-creditcollection@99.9.1
- cxpw-offers@99.9.1
- app-data-ist@2.1.6
- requestor-util@99.9.1
- @dreamguyxeon/libsignal-node@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.