block_package@1.0.0
Malicious code in block_package (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1204.002 · Malicious File
Analysis
The postinstall hook in block_package@1.0.0 downloads a remote binary from hxxp://renes[.]sg/npm_block_package[.]msi and executes it on the installer's machine using Windows 'start' command, with all output suppressed. The package's main source file is a placeholder and provides no legitimate functionality. IOC: renes[.]sg (C2/download host).
- analyzed by
- Leitwacht
- first seen
- Jul 23, 2026, 09:15 PM
- analyzed
- Jul 23, 2026, 09:15 PM
Related advisories
- ai-pro-sdk@2.0.3
- dotnet-runtime-base@1.0.5
- txs-runner-lib@1.0.1
- express-route-engine@3.6.6
- testudo-pack@1.0.0
- testis-pack@1.0.0
- @vite-ln/build-ts@5.17.0
- @vite-tab/tab@5.7.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.