Logo
npm

runhelper@1.0.0

Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 7:13 AM UTC

Malicious

OSV ID

MAL-2026-17332

Ecosystem

npm

Summary

On require('runhelper'), index.js unconditionally loads a payload file staged by its dependency imgbundle at cdn-img-fetch/.runtime/rt.jpg, allocates executable memory via kernel32 VirtualAlloc with PAGE_EXECUTE_READWRITE (0x40) and MEM_COMMIT|MEM_RESERVE (0x3000) through the koffi FFI, copies the file bytes with RtlMoveMemory, and executes them with CreateThread. The payload file is deleted after launch, and an fs.watch waits for it if not yet present. The .jpg extension in a hidden .runtime directory disguises an executable payload, and all errors are swallowed with empty catch (_) {} blocks. The advertised exec() spawn wrapper described in the README is a cover story: the module's top-level behavior on load is native shellcode execution. The manifest pins imgbundle@^1.0.0 (payload source) and koffi@^2.8.0 (FFI used to run it); the loader/payload split means anything that transitively requires runhelper on Windows fetches and executes attacker-supplied native code in-process.

Source: amazon-inspector (3b30a78c30f51a72d8501b77d0cf6190319b8876ed7a119cc2f885adc3618212)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.