LWA-2026-11911 MAL-2026-15991 ↗ confirmed malware

jwt-logger@2.1.9

Malicious code in jwt-logger (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 Channel

Analysis

jwt-logger@2.1.9 is a trojanized clone of the legitimate jwt-logger package. Its main entry point (jwt-logger.js) is a heavily obfuscated multi-stage dropper. On require, it creates a hidden working directory under the system temp dir, writes a second-stage obfuscated payload and a package.json there, and runs `npm install` to pull in axios, better-sqlite3, node-machine-id, socket[.]io-client, and koffi (koffi@3.1.2 on Windows). It then spawns detached child processes (windowsHide, detached) to execute the second stage, and on Windows invokes wscript.exe with a main.vbs script. The installed dependencies indicate machine fingerprinting (node-machine-id), browser/credential database access (better-sqlite3), a socket[.]io command-and-control channel (socket[.]io-client), and HTTP exfiltration (axios). The package also declares a self-dependency on a non-existent version (jwt-logger@^2.3.7).

analyzed by
Leitwacht
first seen
Sep 5, 2026, 11:04 PM
analyzed
Sep 5, 2026, 11:05 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.