jwt-logger@2.1.9
Malicious code in jwt-logger (npm)
Analysis
jwt-logger@2.1.9 is a trojanized clone of the legitimate jwt-logger package. Its main entry point (jwt-logger.js) is a heavily obfuscated multi-stage dropper. On require, it creates a hidden working directory under the system temp dir, writes a second-stage obfuscated payload and a package.json there, and runs `npm install` to pull in axios, better-sqlite3, node-machine-id, socket[.]io-client, and koffi (koffi@3.1.2 on Windows). It then spawns detached child processes (windowsHide, detached) to execute the second stage, and on Windows invokes wscript.exe with a main.vbs script. The installed dependencies indicate machine fingerprinting (node-machine-id), browser/credential database access (better-sqlite3), a socket[.]io command-and-control channel (socket[.]io-client), and HTTP exfiltration (axios). The package also declares a self-dependency on a non-existent version (jwt-logger@^2.3.7).
- analyzed by
- Leitwacht
- first seen
- Sep 5, 2026, 11:04 PM
- analyzed
- Sep 5, 2026, 11:05 PM
Related advisories
- eth-query-utils@1.0.0
- eth-lib-helpers@1.0.0
- gas-price-checker@1.0.0
- @lekzo_dev/amprem@1.0.4
- afhmxiewpsf@1.0.0
- 2nestjs@0.0.1
- 1nestjs@0.0.1
- 0nestjs@0.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.