webpack-patch@1.1.7
Malicious code in webpack-patch (npm)
Analysis
A trojanized clone of the pino logger published under the combosquat name "webpack-patch". The package's index.js exports a function that spawns a detached background Node.js child process running lib/caller.js, hidden via stdio:ignore and child.unref(). caller.js uses axios to fetch a second-stage payload from hxxps://jsonkeeper[.]com/b/XRGF3 (with an 'x-secret-key' request header), then evaluates the response's .cookie field using the Function constructor with the Node.js require() object passed in — giving the remote code full filesystem and network access. Errors are silently retried up to 5 times for stealth. The fetched payload can execute arbitrary code on the installer's machine without their knowledge.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 02:43 AM
- analyzed
- Jun 16, 2026, 02:45 AM
Related advisories
- wao@0.41.2
- stylelint-standard@1.2.0
- macos-ci-utils@1.0.1
- react-next-dom@1.1.7
- node-pino@2.3.2
- chai-utils-test@4.5.4
- autotel-mongoose@2.0.5
- autotel-mongoose@3.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.