LWA-2026-11780 MAL-2026-15602 ↗ confirmed malware

redis-cookie-server@1.0.0

Malicious code in redis-cookie-server (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

redis-cookie-server@1.0.0 is a renamed copy of the supertest HTTP-testing library (its code is verbatim supertest, and its manifest points at the supertest repository) that declares a dependency on the malicious package eslint-prettier-js@^0.0.1. Installing redis-cookie-server transitively installs and executes eslint-prettier-js, which carries the malicious payload. The package name and description are unrelated to the actual code, and the malicious behaviour is delivered through the injected dependency rather than the bundled source.

analyzed by
Leitwacht
first seen
Aug 31, 2026, 02:47 AM
analyzed
Aug 31, 2026, 02:47 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.