ssr-auth-sync@1.6.16
Malicious code in ssr-auth-sync (npm)
Analysis
ssr-auth-sync@1.6.16 is a trojanized clone of the pino logger shipped under a misleading package name. When the package is imported, lib/writer.js executes immediately: it collects environment variables, hostname, platform, username, and MAC addresses, then fetches a second-stage payload from hxxps://www[.]jsonkeeper[.]com/b/PJNZP via axios and executes it via eval(), enabling full remote code execution. A backup C2 URL (hxxps://www[.]jsonkeeper[.]com/b/HY6M6) is also embedded. The harvested system data is passed to the second stage, which can exfiltrate credentials, tokens, or other sensitive information at the attacker's discretion.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 11:55 AM
- analyzed
- Jun 16, 2026, 11:56 AM
Related advisories
- zgmiai-claude-code@1.0.56
- zetrix-development-utils@1.0.2
- nat-ulid@3.0.2
- xz-c-d@1.5.3
- xpna-context@1.0.2
- xmr-btc-lib-js@1.2.1
- uidai_reusable_components@0.4.2
- xboxauthwrapper@3.9.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.