—
MAL-2026-16173
Malicious code in id79-client (npm)
Details
This package is part of a malicious npm campaign published by the `biz44` account. Importing the package automatically launches a detached JavaScript loader that retrieves and executes additional code from npoint.io. The retrieved payload communicates with an attacker-controlled server and implements clipboard collection, keyboard and mouse event collection, filesystem scanning, and theft of Chrome extension storage.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/id79-client
No fixed version published yet for id79-client (npm). Pin to a known-safe version or switch to an alternative.