jsontoken-extend@1.0.13
Malicious code in jsontoken-extend (npm)
Analysis
Combosquat of jsonwebtoken (name: jsontoken-extend). sign.js contains an IIFE that runs on require(): fetch(atob('aHR0cHM6Ly93d3cuanNvbmtlZXBlci5jb20vYi9YQU1SSw==')) -> hxxps://www[.]jsonkeeper[.]com/b/XAMRK, parses JSON response and evals data.content — classic remote code execution dropper. A second commented-out block targets a different jsonkeeper[.]com URL. No token-theft markers, but the package is a supply-chain trojan: it impersonates the popular JWT library and executes attacker-controlled code from a remote paste service on import. Publisher uses free Outlook email; deps include deprecated request and execp.
- analyzed by
- Leitwacht
- first seen
- Jun 8, 2026, 06:34 PM
- analyzed
- Jun 8, 2026, 06:35 PM
Related advisories
- events-runtime@3.2.1
- @concerns/i18n@99.9.1
- @coterie-baby/common@99.9.1
- unleash-js@99.9.1
- wm-mapper@99.9.1
- @ethers-js/contracts@6.9.0
- @solana-js/web3@1.91.3
- @reducers/projects@99.9.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.