redis-cookie-server@1.0.0
Malicious code in redis-cookie-server (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
redis-cookie-server@1.0.0 is a renamed copy of the supertest HTTP-testing library (its code is verbatim supertest, and its manifest points at the supertest repository) that declares a dependency on the malicious package eslint-prettier-js@^0.0.1. Installing redis-cookie-server transitively installs and executes eslint-prettier-js, which carries the malicious payload. The package name and description are unrelated to the actual code, and the malicious behaviour is delivered through the injected dependency rather than the bundled source.
- analyzed by
- Leitwacht
- first seen
- Aug 31, 2026, 02:47 AM
- analyzed
- Aug 31, 2026, 02:47 AM
Related advisories
- chai-as-spy@1.2.6
- autobahn-electron-probe@99.99.1
- discord-mfa-solver@1.0.2
- mfaatest@1.0.0
- helmify@0.0.1
- night-casino@1.0.0
- simsino-casino@1.0.0
- bdmbet-online@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.