Malicious code in llama-tokenizer (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (b22305b1026f27be6d5b78dc19f7db7a05cc9d1818b7ebc7cda0fce92431aa02) This package typosquats llama-tokenizer-js. On require, index.js reconstructs a host and URL path from String.fromCharCode numeric arrays, downloads a platform-specific binary from https://filament-zap.vercel.app/service/assets/fetchBinary (Windows) or /service/assets/fetchLinuxBinary (Linux), writes it to %LOCALAPPDATA%/Programs/WinMetrics/WinService.exe on Windows or ~/.local/share/WinMetrics/WinMetrics on Linux, chmods it 0755 on Linux, and spawns it detached with stdio ignored. The fetch destination is unrelated to any tokenizer publisher, is obfuscated via char-code arrays, and the downloaded bytes are executed with no hash or signature verification. index.js then re-exports the real llama-tokenizer-js as a functional cover so consumers observe the expected tokenizer API while the dropper has already fired.
AI Analysis
Technical Summary
The malicious 'llama-tokenizer' npm package (version 1.2.2) acts as a typosquatting clone of 'llama-tokenizer-js'. Its main script uses obfuscated character code arrays to build URLs pointing to a third-party domain (filament-zap.vercel.app) from which it downloads platform-specific binaries for Windows or Linux. These binaries are saved to local user directories (%LOCALAPPDATA% on Windows, ~/.local/share on Linux), permissioned (chmod 0755 on Linux), and executed in a detached manner with no standard input/output streams. The package then re-exports the genuine 'llama-tokenizer-js' API, serving as a functional cover while the malicious binary runs undetected. No hash or signature verification is performed on the downloaded binaries, increasing risk of arbitrary code execution.
Potential Impact
This malicious package enables remote code execution on the host system by downloading and running an unverified binary payload. The execution occurs silently and detached, potentially allowing attackers to maintain persistence or perform further malicious actions without immediate detection. The obfuscation and API cover reduce the likelihood of discovery during normal use of the tokenizer functionality.
Mitigation Recommendations
No official patch or remediation is currently available. Users should avoid installing or using 'llama-tokenizer' version 1.2.2 from untrusted sources. Verify package authenticity and prefer the legitimate 'llama-tokenizer-js' package. Monitor for suspicious binaries in local user directories and remove any unauthorized executables. Consider using package integrity verification tools and supply chain security measures to prevent installation of typosquatting or malicious packages.
Malicious code in llama-tokenizer (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (b22305b1026f27be6d5b78dc19f7db7a05cc9d1818b7ebc7cda0fce92431aa02) This package typosquats llama-tokenizer-js. On require, index.js reconstructs a host and URL path from String.fromCharCode numeric arrays, downloads a platform-specific binary from https://filament-zap.vercel.app/service/assets/fetchBinary (Windows) or /service/assets/fetchLinuxBinary (Linux), writes it to %LOCALAPPDATA%/Programs/WinMetrics/WinService.exe on Windows or ~/.local/share/WinMetrics/WinMetrics on Linux, chmods it 0755 on Linux, and spawns it detached with stdio ignored. The fetch destination is unrelated to any tokenizer publisher, is obfuscated via char-code arrays, and the downloaded bytes are executed with no hash or signature verification. index.js then re-exports the real llama-tokenizer-js as a functional cover so consumers observe the expected tokenizer API while the dropper has already fired.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The malicious 'llama-tokenizer' npm package (version 1.2.2) acts as a typosquatting clone of 'llama-tokenizer-js'. Its main script uses obfuscated character code arrays to build URLs pointing to a third-party domain (filament-zap.vercel.app) from which it downloads platform-specific binaries for Windows or Linux. These binaries are saved to local user directories (%LOCALAPPDATA% on Windows, ~/.local/share on Linux), permissioned (chmod 0755 on Linux), and executed in a detached manner with no standard input/output streams. The package then re-exports the genuine 'llama-tokenizer-js' API, serving as a functional cover while the malicious binary runs undetected. No hash or signature verification is performed on the downloaded binaries, increasing risk of arbitrary code execution.
Potential Impact
This malicious package enables remote code execution on the host system by downloading and running an unverified binary payload. The execution occurs silently and detached, potentially allowing attackers to maintain persistence or perform further malicious actions without immediate detection. The obfuscation and API cover reduce the likelihood of discovery during normal use of the tokenizer functionality.
Mitigation Recommendations
No official patch or remediation is currently available. Users should avoid installing or using 'llama-tokenizer' version 1.2.2 from untrusted sources. Verify package authenticity and prefer the legitimate 'llama-tokenizer-js' package. Monitor for suspicious binaries in local user directories and remove any unauthorized executables. Consider using package integrity verification tools and supply chain security measures to prevent installation of typosquatting or malicious packages.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10163
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a520ec968715ace438f5fe4
Added to database: 07/11/2026, 09:37:13 UTC
Last enriched: 07/11/2026, 09:57:18 UTC
Last updated: 07/28/2026, 17:59:52 UTC
Views: 27
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.