LWA-2026-5150 MAL-2026-2905 ↗ confirmed malware

simple-auth-basic@2.0.2

Malicious code in simple-auth-basic (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

Combosquat of the basic-auth package. When imported, the module executes two eval(atob(...)) calls at runtime that fetch remote JavaScript from hxxps://coingecko-liard[.]vercel[.]app/api/content and hxxps://coingecko-liard[.]vercel[.]app/api/old, then eval the response. This gives the attacker full remote code execution in the context of the importing application. The package ships no detection of the C2 host in its listed dependencies (it requires axios at runtime but does not declare it in package.json).

analyzed by
Leitwacht
first seen
Jun 13, 2026, 11:17 PM
analyzed
Jun 13, 2026, 11:18 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.