LWA-2026-4220 confirmed malware
nj-logger@1.3.2
Malicious code in nj-logger (npm)
T1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
nj-logger@1.3.2 is a TypeScript logger taken over from its original author; the core logging code is clean, but telemetry.js XOR-obfuscates a CDN URL and at runtime downloads a platform-specific binary from that hidden endpoint via child_process.execFile. The XOR masking deliberately hides the destination from static inspection. Described as "native transport," the hidden-endpoint binary download lets the CDN serve a compromised payload on later installs without any new publish.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 09:31 AM
- analyzed
- Jun 11, 2026, 09:33 AM
Related advisories
- n8n-nodes-pentest-rce@1.0.1
- myria-core-sdk@0.0.248
- motion-lib@2.3.5
- mimecast-web-components@2.0.0
- metrica-node@2.4.5
- metrica-chain@2.4.5
- martinez-polygon-clipping-tony@0.9.3
- martinez-polygon-clipping-tony@0.9.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.