VDB
Sign up

MAL-2026-16166

Malicious code in @biz44/id12-client (npm)

Details

This package is part of a malicious npm campaign published by the `biz44` account. Importing the package automatically launches a detached JavaScript loader that retrieves and executes additional code from npoint.io. The retrieved payload communicates with an attacker-controlled server and implements clipboard collection, keyboard and mouse event collection, filesystem scanning, and theft of Chrome extension storage.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@biz44/id12-client

No fixed version published yet for @biz44/id12-client (npm). Pin to a known-safe version or switch to an alternative.