req-parmas-valid@1.0.2
Malicious code in req-parmas-valid (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1082 · System Information Discovery
Analysis
req-parmas-valid@1.0.2 is a typosquat of the 'request' HTTP library (a misspelling of 'params' with 'valid' appended). On require(), index.js spawns a detached node child process running lib/callers.js, which makes an HTTPS GET to jsonkeeper[.]com/b/DDC6J with a custom X-Secret-Key header and executes the response via the Function constructor with full require access, delivering a second-stage payload. The package is a single-version burst from a throwaway domain and impersonates the real request project's GitHub bugs URL.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 10:33 PM
- analyzed
- Jun 11, 2026, 10:34 PM
Related advisories
- oprnm@1.0.0
- opentelemetry-plugin-graphql-example@55.33.111
- opentracing-shim@55.33.111
- opentelemetry-contrib-scripts@55.33.111
- openclaw-preview@2026.6.1
- worker-build@9.0.1
- index-ulid@3.0.2
- oc-navbar-module-client@9.9.10
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.