Supply-chain threat intelligence

Incident detail

criticalnpm·obfuscation·github

Malicious code in nano-perf (npm)

nano-perf

Risk score

92

AI summary

Indexed incident for nano-perf (npm).

Description

Version 2.2.0 of nano-perf declares a postinstall script that automatically launches daemon.js as a detached, unreferenced process with ignored standard streams, allowing it to survive completion of npm install. The launcher reconstructs an obfuscated Supabase endpoint from Base64 fragments and sends a persistent node identifier, CPU count, total memory, platform information, and an online heartbeat to a table named stealth_heartbeats.

After a successful heartbeat the detached daemon polls a second table named stealth_tasks for pending work assigned to the victim node. The observed task handlers perform CPU benchmarking and system probing and upload the results. Although this version does not expose an arbitrary shell task, the hidden endpoint, automatic installation-time persistence, periodic beaconing, system fingerprint collection, and remote task polling are behavior of a covert C2 beacon and task agent rather than a performance utility.


Credit: OpenSSF (source)

Technical details

Indicators

  • ghsa
    95%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents