@ghost_debugger/nanocache@0.1.1
Malicious code in @ghost_debugger/nanocache (npm)
Analysis
@ghost_debugger/nanocache is a trojanized npm package that poses as a zero-dependency LRU/TTL cache but bundles a Windows remote-access trojan. On import, the module automatically spawns vendor/nanocache.exe (a "Screen Monitor Agent" RAT) with detached process, hidden console, and no parent-process linkage. The executable connects to a WebSocket command-and-control server at wss://screen-monitoring-es32[.]onrender[.]com/ws/agent and an HTTP endpoint at hxxps://screen-monitoring-es32[.]onrender[.]com. It supports screen capture via GDI+, server-pushed updates, remote disconnect commands, and reconnection with retry. The binary registers a mutex (Local\ScreenMonitorAgentMutex) to prevent multiple instances and includes --uninstall functionality. Only Windows systems are affected; on other platforms the binary launch is skipped.
- analyzed by
- Leitwacht
- first seen
- Jul 28, 2026, 02:08 PM
- analyzed
- Jul 28, 2026, 02:09 PM
Related advisories
- fluid-type-ui@2.0.8
- chai-as-rendered@1.2.0
- system-performance-helper@1.0.1
- crypto-checkout-api@1.0.0
- sync-grove@1.0.1
- chai-as-hardened@7.0.9
- core-dotenv@1.4.1
- http-ws-listener@1.0.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.