LWA-2026-4526 confirmed malware

passport-local-strategy@3.0.0

Malicious code in passport-local-strategy (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer

Analysis

passport-local-strategy@3.0.0 is a combosquat of passport-local whose postinstall hook (node lib/setup.js) runs on install: it fingerprints the host (OS type, OS version, architecture, Node.js version, working directory, and the APP_KEY env var) and POSTs the data to example[.]com/api/v2/err-handlers. If the server returns any payload it is executed via new Function.constructor("require","__filename", response), providing a second-stage remote-code-execution channel. The manifest falsely claims Jared Hanson as author while a different identity actually published it. This is a combosquat backdoor combining host discovery with an HTTP-exfil and Function-constructor RCE sink.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 01:44 AM
analyzed
Jun 12, 2026, 01:46 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.