utility-kit-ts@1.3.2
Malicious code in utility-kit-ts (npm)
Analysis
utility-kit-ts@1.3.2 is a trojanized package impersonating a TypeScript utility library. When imported, it fetches a second-stage JavaScript payload from a hardcoded C2 server at 31[.]97[.]137[.]157:45000 via HTTP GET to /icons/109 (with custom header bearrtoken: "logo") and executes the response using the Function constructor with full Node.js API access (require, process, Buffer, setTimeout, etc.) passed into the eval context. The fetched code can perform arbitrary operations on the host. The package claims to be dependency-free but ships with heavy dependencies (axios, better-sqlite3, socket[.]io-client, node-machine-id, express) inconsistent with its stated purpose.
- analyzed by
- Leitwacht
- first seen
- Jul 22, 2026, 10:44 AM
- analyzed
- Jul 22, 2026, 10:44 AM
Related advisories
- ts-toolkit-plus@1.3.2
- ventrix-kit@1.5.2
- vectormark@1.0.0
- chai-as-stringify@7.0.2
- chai-as-format@2.3.5
- tailwindcss-form-components@1.5.0
- chai-as-deployer@2.3.6
- chai-foundry@7.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.