malware npm

bytecraft

discovered 2026-06-17

XOR utility library (xor(), rotate, hex/base64). Provides the xor() primitive the procwire dropper uses to decode endpointmap's _ep/_p byte arrays. No install hook; benign-looking in isolation but a deliberate component of the split dropper. Maintainer [email protected], fabricated GitHub org vpetrov-oss.

Threat types

other

Malicious versions

  • 1.5.0 · 5eb6958c8ea044df…

Campaigns

Indicators

Read the full analysis →