LWA-2026-4220 confirmed malware

nj-logger@1.3.2

Malicious code in nj-logger (npm)

T1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

nj-logger@1.3.2 is a TypeScript logger taken over from its original author; the core logging code is clean, but telemetry.js XOR-obfuscates a CDN URL and at runtime downloads a platform-specific binary from that hidden endpoint via child_process.execFile. The XOR masking deliberately hides the destination from static inspection. Described as "native transport," the hidden-endpoint binary download lets the CDN serve a compromised payload on later installs without any new publish.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 09:31 AM
analyzed
Jun 11, 2026, 09:33 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.