Logo
npm

fsbrowse@0.2.28

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 5:38 AM UTC

Malicious

OSV ID

MAL-2026-13722

Ecosystem

npm

Summary

The package's main entry file (index.js) contains a legitimate Express file-server module followed by a unicode-escape-obfuscated IIFE appended after whitespace padding. When the module is loaded (via require('fsbrowse'), server.js, or the fsbrowse bin), the trailing code queries Ethereum RPC endpoints (eth.blockscout.com, 1rpc.io/eth, eth.drpc.org, ethereum-rpc.publicnode.com, eth-mainnet.public.blastapi.io) for the latest outgoing transaction of hardcoded address 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a, decodes two IPv4 addresses from the transaction to field, then fetches XOR-encrypted payloads from those hosts over http://<ip>:443/0x/cls and executes the decrypted Node code via eval and via spawn('node', ['-e',...], { detached: true, stdio: 'ignore' }). Core module names (http, https, zlib, url, child_process), method names (spawn, eth_getBlockByNumber, eth_getTransactionCount), destination URLs, the Ethereum address, and XOR keys are all written as \u00XX escape sequences to hide the behavior from casual review. This is the EtherHiding technique: on-chain resolution of C2 IPs to defeat static blocklists, followed by fetch-and-execute of attacker-supplied code with the installer's privileges at import time.

Source: amazon-inspector (5b7866973ba5f2971efedd027cce57aefb5b8f27d7304de323261832c29bbd82)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.