simple-auth-basic@2.0.2
Malicious code in simple-auth-basic (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
Combosquat of the basic-auth package. When imported, the module executes two eval(atob(...)) calls at runtime that fetch remote JavaScript from hxxps://coingecko-liard[.]vercel[.]app/api/content and hxxps://coingecko-liard[.]vercel[.]app/api/old, then eval the response. This gives the attacker full remote code execution in the context of the importing application. The package ships no detection of the C2 host in its listed dependencies (it requires axios at runtime but does not declare it in package.json).
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 11:17 PM
- analyzed
- Jun 13, 2026, 11:18 PM
Related advisories
- environment-gate@7.3.6
- session-exp@1.3.20
- mailconfirmer@3.3.12
- server-up-ndot@1.0.0
- sentrykit@30.0.0
- search-reservation@55.0.0
- rollup-runtime-polyfill-core@0.13.5
- rollup-packages-polyfill-core@0.5.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.