This package is part of a malicious npm campaign published by the biz44 account. Importing the package automatically launches a detached JavaScript loader that retrieves and executes additional code from npoint.io. The retrieved payload communicates with an attacker-controlled server and implements clipboard collection, keyboard and mouse event collection, filesystem scanning, and theft of Chrome extension storage.
{
"iocs": {
"ips": [
"103.170.217.184"
],
"urls": [
"https://api.npoint.io/641d37178a880b1e8b8f",
"https://api.npoint.io/33e8d008c334b060adad",
"https://api.npoint.io/933a731a5e97f4b45249",
"https://api.npoint.io/24c25d5f5fcbb0992a4f",
"https://api.npoint.io/ddae72efbb6714fae922",
"https://api.npoint.io/37c0a0c68bf7a94ed731",
"http://103.170.217.184:8787"
]
}
}