Malicious code in native-runner (npm)
The npm package 'native-runner' contains malicious code that, upon import, silently waits for and executes a hidden binary named node_runtime_helper.exe from a Windows system-like directory. This behavior occurs as a side effect of requiring the package, without any explicit API call. The package depends on 'img-to-native', which places the malicious binary on the system. This drop-and-execute chain can lead to full system compromise, and removal of the package does not guarantee eradication of the malware.
AI Analysis
Technical Summary
The 'native-runner' npm package includes a top-level immediately-invoked function expression (IIFE) in its index.js that polls for up to two minutes for a binary file at %APPDATA%\Microsoft\Windows\node_runtime_helper.exe. Once detected, it launches this binary detached and hidden, allowing the process to run without user visibility or output capture. The package's only declared dependency, 'img-to-native@^1.0.0', is not used in code but is responsible for placing the malicious binary at the hardcoded path. Together, these packages form a drop-and-execute malware chain that compromises any system where 'native-runner' is installed or imported.
Potential Impact
Any system with 'native-runner' installed or running is considered fully compromised. The attacker gains persistent, hidden execution capabilities via the dropped binary. All secrets and keys stored on the compromised machine should be considered exposed and must be rotated immediately from a secure environment. Simply removing the package does not guarantee removal of all malicious components or persistence mechanisms.
Mitigation Recommendations
Remove the 'native-runner' package immediately. Rotate all secrets and keys stored on the affected machine from a different, trusted device. Conduct a thorough system investigation and remediation, as the malicious binary runs detached and hidden and may have established persistence or additional backdoors. There is no official patch or fix available; the package itself is malicious. Avoid installing or importing this package.
Malicious code in native-runner (npm)
Description
The npm package 'native-runner' contains malicious code that, upon import, silently waits for and executes a hidden binary named node_runtime_helper.exe from a Windows system-like directory. This behavior occurs as a side effect of requiring the package, without any explicit API call. The package depends on 'img-to-native', which places the malicious binary on the system. This drop-and-execute chain can lead to full system compromise, and removal of the package does not guarantee eradication of the malware.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'native-runner' npm package includes a top-level immediately-invoked function expression (IIFE) in its index.js that polls for up to two minutes for a binary file at %APPDATA%\Microsoft\Windows\node_runtime_helper.exe. Once detected, it launches this binary detached and hidden, allowing the process to run without user visibility or output capture. The package's only declared dependency, 'img-to-native@^1.0.0', is not used in code but is responsible for placing the malicious binary at the hardcoded path. Together, these packages form a drop-and-execute malware chain that compromises any system where 'native-runner' is installed or imported.
Potential Impact
Any system with 'native-runner' installed or running is considered fully compromised. The attacker gains persistent, hidden execution capabilities via the dropped binary. All secrets and keys stored on the compromised machine should be considered exposed and must be rotated immediately from a secure environment. Simply removing the package does not guarantee removal of all malicious components or persistence mechanisms.
Mitigation Recommendations
Remove the 'native-runner' package immediately. Rotate all secrets and keys stored on the affected machine from a different, trusted device. Conduct a thorough system investigation and remediation, as the malicious binary runs detached and hidden and may have established persistence or additional backdoors. There is no official patch or fix available; the package itself is malicious. Avoid installing or importing this package.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-17218
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-jxw5-69p3-hpm4"]
- Ecosystems
- ["npm"]
Threat ID: 6abb4186f7a7c54106cc2f73
Added to database: 09/29/2026, 04:41:42 UTC
Last enriched: 09/29/2026, 04:46:50 UTC
Last updated: 09/29/2026, 10:19:01 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.