id79-client@1.1.79
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 7:32 AM UTC
OSV ID
MAL-2026-16173
Ecosystem
npm
Summary
On import, index.js calls initialize() which spawns a detached, stdio-suppressed node loader.js child process. loader.js issues an HTTPS GET to https://api.npoint.io/24c12c4b66a29747764f, base64-decodes the code field of the response, and executes it via new Function(require, __dirname, __filename, module, exports, decodedCode) — arbitrary code from a third-party mutable JSON hosting bin runs with full Node privileges on the installer's machine. loader.js additionally monkey-patches Module.prototype.require so any subsequent require('child_process').spawn/execSync call is rewritten to force windowsHide:true and route execSync through a hidden cmd.exe /c spawnSync, ensuring commands issued by the remotely fetched payload run invisibly on Windows. The detached-and-unref'd child, suppressed stdio, and stealth child_process wrapper are consistent with a persistent covert loader whose actual behavior is controlled by whoever owns the npoint bin.
Source: amazon-inspector (8e7016cebc45328009f3b55af011e7d5d4db068ea04d85602cac0aeafbe3637e)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.