LWA-2026-11618 confirmed malware
commonjs-code-token@1.0.0
Malicious code in commonjs-code-token (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
The postinstall hook runs index.js, which fetches hxxps://access-token-delta[.]vercel[.]app and executes (eval) the `token` value returned in the JSON response. This downloads and runs arbitrary remote code at install time. The package advertises itself as an in-memory cache but contains no cache logic — only the remote code loader.
- analyzed by
- Leitwacht
- first seen
- Aug 25, 2026, 07:07 PM
- analyzed
- Aug 25, 2026, 07:07 PM
Related advisories
- chai-plus@6.2.5
- r4wk-book@2.2.2
- chai-as-otc@1.0.5
- hydration-cls-ui@1.0.0
- mham-js@1.0.4
- dim-hydration-ui@1.0.0
- dims-hydration-ui@1.0.0
- auth-otp@1.0.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.