jsontoken-extend@1.0.13
Malicious code in jsontoken-extend (npm)
Analysis
Combosquat of jsonwebtoken (name: jsontoken-extend). sign.js contains an IIFE that runs on require(): fetch(atob('aHR0cHM6Ly93d3cuanNvbmtlZXBlci5jb20vYi9YQU1SSw==')) -> hxxps://www[.]jsonkeeper[.]com/b/XAMRK, parses JSON response and evals data.content — classic remote code execution dropper. A second commented-out block targets a different jsonkeeper[.]com URL. No token-theft markers, but the package is a supply-chain trojan: it impersonates the popular JWT library and executes attacker-controlled code from a remote paste service on import. Publisher uses free Outlook email; deps include deprecated request and execp.
- analyzed by
- Leitwacht
- first seen
- Jun 8, 2026, 06:34 PM
- analyzed
- Jun 8, 2026, 06:35 PM
Related advisories
- events-runtime@3.2.1
- @concerns/i18n@99.9.1
- @coterie-baby/common@99.9.1
- unleash-js@99.9.1
- wm-mapper@99.9.1
- dotenv-runtime@1.0.0
- css-jptvix-polyfill@1.0.0
- tailwind-forms-kit@0.5.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.