MAL-2026-16168

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@biz44/id79-client/MAL-2026-16168.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-16168
Published
2026-09-12T13:51:48Z
Modified
2026-09-15T06:30:04Z
Summary
Malicious code in @biz44/id79-client (npm)
Details

This package is part of a malicious npm campaign published by the biz44 account. Importing the package automatically launches a detached JavaScript loader that retrieves and executes additional code from npoint.io. The retrieved payload communicates with an attacker-controlled server and implements clipboard collection, keyboard and mouse event collection, filesystem scanning, and theft of Chrome extension storage.

Database specific
{
    "iocs":  {
        "ips":  [
            "103.170.217.184"
        ],
        "urls":  [
            "https://api.npoint.io/24c12c4b66a29747764f",
            "https://api.npoint.io/37c0a0c68bf7a94ed731",
            "http://103.170.217.184:8787"
        ]
    }
}
Credits
    • ESTsecurity - FINDER

Affected packages

npm / @biz44/id79-client

Package

Name
@biz44/id79-client
View open source insights on deps.dev
Purl
pkg:npm/%40biz44/id79-client

Affected ranges

Affected versions

1.*
1.1.80

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@biz44/id79-client/MAL-2026-16168.json"