LWA-2026-5562 MAL-2026-5934 ↗ confirmed malware

ssr-auth-sync@1.6.16

Malicious code in ssr-auth-sync (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 Channel

Analysis

ssr-auth-sync@1.6.16 is a trojanized clone of the pino logger shipped under a misleading package name. When the package is imported, lib/writer.js executes immediately: it collects environment variables, hostname, platform, username, and MAC addresses, then fetches a second-stage payload from hxxps://www[.]jsonkeeper[.]com/b/PJNZP via axios and executes it via eval(), enabling full remote code execution. A backup C2 URL (hxxps://www[.]jsonkeeper[.]com/b/HY6M6) is also embedded. The harvested system data is passed to the second stage, which can exfiltrate credentials, tokens, or other sensitive information at the attacker's discretion.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 11:55 AM
analyzed
Jun 16, 2026, 11:56 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.