OpenSSF/OSV advisory MAL-2026-16172 confirms this npm version as malicious. This package is part of a malicious npm campaign published by the `biz44` account. Importing the package automatically launches a detached JavaScript loader that retrieves and executes additional code from npoint.io. The retrieved payload communicates with an attacker-controlled server and implements clipboard collection, keyboard and mouse event collection, filesystem scanning, and theft of Chrome extension storage.
This report applies to @biz44/runtime-utils@1.1.96.
1.1.100, 1.1.11, 1.1.13, 1.1.81, 1.1.96
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.