LWA-2026-11647 confirmed malware
js-tokens-array@1.0.0
Malicious code in js-tokens-array (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
The postinstall hook runs index.js, which fetches a JSON payload from hxxps://access-token-delta[.]vercel[.]app/ and executes the returned value with eval() at install time. The fetched content is fully attacker-controlled, giving the remote host arbitrary code execution on any machine that installs the package. The C2 endpoint is access-token-delta[.]vercel[.]app (HTTPS).
- analyzed by
- Leitwacht
- first seen
- Aug 26, 2026, 08:25 PM
- analyzed
- Aug 26, 2026, 08:25 PM
Related advisories
- date-fns-sync@1.0.0
- supersignaturenature@1.0.5
- external_deps_enjoyer@1.0.0
- zenntechinc-cli@1.6.4
- hydration-vli-ui@1.0.0
- commonjs-code-token@1.0.0
- chai-plus@6.2.5
- r4wk-book@2.2.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.