LWA-2026-7021 MAL-2026-12493 ↗ confirmed malware

utility-kit-ts@1.3.2

Malicious code in utility-kit-ts (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information Discovery

Analysis

utility-kit-ts@1.3.2 is a trojanized package impersonating a TypeScript utility library. When imported, it fetches a second-stage JavaScript payload from a hardcoded C2 server at 31[.]97[.]137[.]157:45000 via HTTP GET to /icons/109 (with custom header bearrtoken: "logo") and executes the response using the Function constructor with full Node.js API access (require, process, Buffer, setTimeout, etc.) passed into the eval context. The fetched code can perform arbitrary operations on the host. The package claims to be dependency-free but ships with heavy dependencies (axios, better-sqlite3, socket[.]io-client, node-machine-id, express) inconsistent with its stated purpose.

analyzed by
Leitwacht
first seen
Jul 22, 2026, 10:44 AM
analyzed
Jul 22, 2026, 10:44 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.