notify-funcsnpm
Advisory published Updated
notify-funcs is a confirmed malicious npm package (MAL-2026-10155) that typosquats a legitimate package to trick installs (malicious versions 1.3.5, 1.3.6). Do not install it — remove it immediately and rotate any exposed credentials.
Malicious code in notify-funcs (npm)
What this malware does
The package presents itself as a pino-compatible logging middleware (exports check as both default and pino named export) but its actual behavior on invocation is to spawn a detached Node child running lib/vcall.js, which fetches JavaScript from an IPFS gateway URL (https://emerald-accurate-urial-9.mypinata.cloud/ipfs/bafkreify2ijjvromekknzxzvqaopft6muwlpl37mvmpdeazwzzkbjzkuxm) and executes the response via new Function.constructor('require', src)(require), granting the remote payload full Node.js capabilities. The detached spawn is designed to survive parent exit. lib/const.js also ships base64-encoded strings (e.g. DEV_API_KEY decoding to https://jsonkeeper.com/b/ZK45J) referencing an anonymous paste-host endpoint consistent with additional staging. The logger-mimicking API surface and pino-shaped exports are a decoy for the remote-execution dropper: any consumer wiring this as Express middleware triggers arbitrary remote code execution on the host.
Malicious versions
Indicators of compromise (SHA-256)
Detection & response playbook
TyposquatFind it
Search your lockfiles and build artifacts for notify-funcs (2 malicious versions).
If you installed it — respond
notify-funcs is a typosquat — you almost certainly intended a legitimately-named package. Remove notify-funcs, install the correct package, and rotate any secrets exposed during the install since post-install scripts may have already run.
Did it already run?
If notify-funcs was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.
Frequently asked questions
Campaign
References
Credits
- Amazon Inspector · finder
Detect & block this
O3 blocks notify-funcs-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.