environment-gate@7.3.6
Malicious code in environment-gate (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool Transfer
Analysis
Package environment-gate exports a gate() function that fetches JavaScript code from hxxps://www[.]jsonkeeper[.]com/b/VKUNI and executes it via eval(). The remote URL is base64-encoded using atob() inside the function body. When called at runtime, gate() downloads and runs attacker-controlled content from the jsonkeeper[.]com host, enabling arbitrary remote code execution. The prior version (7.3.5) carried a commented-out copy of the same payload, which was activated in 7.3.6.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 09:16 PM
- analyzed
- Jun 13, 2026, 09:18 PM
Related advisories
- session-exp@1.3.20
- mailconfirmer@3.3.12
- server-up-ndot@1.0.0
- sentrykit@30.0.0
- search-reservation@55.0.0
- rollup-runtime-polyfill-core@0.13.5
- rollup-packages-polyfill-core@0.5.0
- rollup-plugin-polyfill-connect@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.