Malicious code in runtimekit (npm)
The npm package 'runtimekit' versions 1.0.1 and 1.0.5 contain malicious code that executes arbitrary JavaScript during module load. The package includes an obfuscated self-executing function that decodes hidden strings to dynamically construct and run code with full Node.js privileges. This behavior occurs when requiring 'runtimekit' or 'runtimekit/readonly', allowing the malicious payload to run in-process. The package falsely advertises itself as a validation/runtime utility but embeds a loader with no legitimate purpose for obfuscation. No official patch or remediation guidance is currently provided.
AI Analysis
Technical Summary
The 'runtimekit' npm package versions 1.0.1 and 1.0.5 include a self-executing Immediately Invoked Function Expression (IIFE) that decodes obfuscated strings to retrieve the Function constructor and dynamically execute arbitrary JavaScript code at module load time. The loader exposes Node.js require and module objects globally to enable the dynamically constructed function to access them outside the module closure. This results in execution of a hidden payload with full Node privileges whenever the package or its 'readonly' submodule is required. The obfuscation and global exposure of Node internals indicate malicious intent, as there is no legitimate reason for such behavior in a runtime utility package. No patch or fix information is provided in the source data.
Potential Impact
Any application or environment that installs and requires 'runtimekit' versions 1.0.1 or 1.0.5 will execute arbitrary, obfuscated JavaScript code with full Node.js privileges. This can lead to compromise of the host environment, unauthorized code execution, data theft, or further malicious activity. The malicious code runs in-process, making detection and containment more difficult. There is no indication of known exploits in the wild yet.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix or official guidance is available, avoid installing or requiring the 'runtimekit' package versions 1.0.1 and 1.0.5. Remove these versions from any environments where they are present. Consider using alternative, trusted packages for runtime or validation utilities. Monitor package sources and supply chain for updates or advisories regarding this package.
Malicious code in runtimekit (npm)
Description
The npm package 'runtimekit' versions 1.0.1 and 1.0.5 contain malicious code that executes arbitrary JavaScript during module load. The package includes an obfuscated self-executing function that decodes hidden strings to dynamically construct and run code with full Node.js privileges. This behavior occurs when requiring 'runtimekit' or 'runtimekit/readonly', allowing the malicious payload to run in-process. The package falsely advertises itself as a validation/runtime utility but embeds a loader with no legitimate purpose for obfuscation. No official patch or remediation guidance is currently provided.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'runtimekit' npm package versions 1.0.1 and 1.0.5 include a self-executing Immediately Invoked Function Expression (IIFE) that decodes obfuscated strings to retrieve the Function constructor and dynamically execute arbitrary JavaScript code at module load time. The loader exposes Node.js require and module objects globally to enable the dynamically constructed function to access them outside the module closure. This results in execution of a hidden payload with full Node privileges whenever the package or its 'readonly' submodule is required. The obfuscation and global exposure of Node internals indicate malicious intent, as there is no legitimate reason for such behavior in a runtime utility package. No patch or fix information is provided in the source data.
Potential Impact
Any application or environment that installs and requires 'runtimekit' versions 1.0.1 or 1.0.5 will execute arbitrary, obfuscated JavaScript code with full Node.js privileges. This can lead to compromise of the host environment, unauthorized code execution, data theft, or further malicious activity. The malicious code runs in-process, making detection and containment more difficult. There is no indication of known exploits in the wild yet.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix or official guidance is available, avoid installing or requiring the 'runtimekit' package versions 1.0.1 and 1.0.5. Remove these versions from any environments where they are present. Consider using alternative, trusted packages for runtime or validation utilities. Monitor package sources and supply chain for updates or advisories regarding this package.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-6477
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a3ef7e527e9c79719032b42
Added to database: 06/26/2026, 22:06:29 UTC
Last enriched: 06/26/2026, 22:44:28 UTC
Last updated: 07/31/2026, 15:06:30 UTC
Views: 136
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.