VDB
Sign up

MAL-2026-16173

Malicious code in id79-client (npm)

Details

This package is part of a malicious npm campaign published by the `biz44` account. Importing the package automatically launches a detached JavaScript loader that retrieves and executes additional code from npoint.io. The retrieved payload communicates with an attacker-controlled server and implements clipboard collection, keyboard and mouse event collection, filesystem scanning, and theft of Chrome extension storage.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/id79-client

No fixed version published yet for id79-client (npm). Pin to a known-safe version or switch to an alternative.