LWA-2026-5487 MAL-2026-5581 ↗ confirmed malware

webpack-patch@1.1.7

Malicious code in webpack-patch (npm)

Analysis

A trojanized clone of the pino logger published under the combosquat name "webpack-patch". The package's index.js exports a function that spawns a detached background Node.js child process running lib/caller.js, hidden via stdio:ignore and child.unref(). caller.js uses axios to fetch a second-stage payload from hxxps://jsonkeeper[.]com/b/XRGF3 (with an 'x-secret-key' request header), then evaluates the response's .cookie field using the Function constructor with the Node.js require() object passed in — giving the remote code full filesystem and network access. Errors are silently retried up to 5 times for stealth. The fetched payload can execute arbitrary code on the installer's machine without their knowledge.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 02:43 AM
analyzed
Jun 16, 2026, 02:45 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.