LWA-2026-4466 MAL-2026-5991 ↗ confirmed malware

req-parmas-valid@1.0.2

Malicious code in req-parmas-valid (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1082 · System Information Discovery

Analysis

req-parmas-valid@1.0.2 is a typosquat of the 'request' HTTP library (a misspelling of 'params' with 'valid' appended). On require(), index.js spawns a detached node child process running lib/callers.js, which makes an HTTPS GET to jsonkeeper[.]com/b/DDC6J with a custom X-Secret-Key header and executes the response via the Function constructor with full require access, delivering a second-stage payload. The package is a single-version burst from a throwaway domain and impersonates the real request project's GitHub bugs URL.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 10:33 PM
analyzed
Jun 11, 2026, 10:34 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.