runhelper@1.0.0
Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 7:13 AM UTC
OSV ID
MAL-2026-17332
Ecosystem
npm
Summary
On require('runhelper'), index.js unconditionally loads a payload file staged by its dependency imgbundle at cdn-img-fetch/.runtime/rt.jpg, allocates executable memory via kernel32 VirtualAlloc with PAGE_EXECUTE_READWRITE (0x40) and MEM_COMMIT|MEM_RESERVE (0x3000) through the koffi FFI, copies the file bytes with RtlMoveMemory, and executes them with CreateThread. The payload file is deleted after launch, and an fs.watch waits for it if not yet present. The .jpg extension in a hidden .runtime directory disguises an executable payload, and all errors are swallowed with empty catch (_) {} blocks. The advertised exec() spawn wrapper described in the README is a cover story: the module's top-level behavior on load is native shellcode execution. The manifest pins imgbundle@^1.0.0 (payload source) and koffi@^2.8.0 (FFI used to run it); the loader/payload split means anything that transitively requires runhelper on Windows fetches and executes attacker-supplied native code in-process.
Source: amazon-inspector (3b30a78c30f51a72d8501b77d0cf6190319b8876ed7a119cc2f885adc3618212)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.