buffer-utilities: Lazarus Group npm Brandjacking Dropper

Confirmed
Discovered Jun 18, 2026

Sonatype and JFrog describe buffer-utilities as a malicious npm brandjacking package in a Lazarus Group campaign; the package acts as a dropper that fetches and launches remote payloads.

3
Affected Packages
13
Observables
3
Sources

Timeline

1 of 1 rows

Timeline
DateEventDescriptionSource
Jun 18, 2026Fresh source reviewReviewed direct and primary sources for the last-two-weeks supply-chain refresh; this preview intentionally excludes older Halting Problems article data.Primary research

Affected Software

3 of 3 rows

Affected Software
PackageEcosystemVersion RangeStatusConfidenceSource
buffer-utilitiesnpm1.0.0Malicious90%Primary research
buffer-utilitiesnpm1.1.0Malicious90%Primary research
buffer-utilitiesnpm1.1.1Malicious90%Primary research

IOC Clipboard

13 IOCs
domainregistry.npmjs.org
urlhttps://registry.npmjs.org/buffer-utilities
urlhttps://registry.npmjs.org/buffer-utilities/-/buffer-utilities-1.0.0.tgz
urlhttps://registry.npmjs.org/buffer-utilities/-/buffer-utilities-1.1.0.tgz
urlhttps://registry.npmjs.org/buffer-utilities/-/buffer-utilities-1.1.1.tgz
urlhttps://registry.npmjs.org/buffer-utilities/-/buffer-utilities-0.0.1-security.tgz
file_pathsetup.cjs
file_path.vscode
file_path.pkg_history
file_path.pkg_logs
commandpostinstall
commandnode setup.cjs --no-warnings
commandspawn(process.execPath, ..., detached: true)

Provenance & Sources

3 of 3 rows

Provenance & Sources
SourceTypeReliabilityClaimsEvidence
Primary researchprimary research95%1https://www.sonatype.com/blog/lazarus-groups-latest-brandjacking-campaign-on-npm
Primary researchprimary research95%1https://research.jfrog.com/post/easy-day-js/
Primary researchprimary research95%1https://registry.npmjs.org/buffer-utilities