authsessionbridge@1.6.29
Malicious code in authsessionbridge (npm)
Analysis
authsessionbridge@1.6.29 is a trojanized clone of the pino logger package: it ships pino's documentation, images, and library files under a false name claiming to handle authentication state synchronization. It contains an injected payload in lib/writer.js that executes on require(). The payload collects host metadata (all environment variables, hostname, operating system/platform, username, and non-loopback MAC addresses via os.networkInterfaces()) and then issues an axios GET request to hxxps://www[.]jsonkeeper[.]com/b/PJNZP, executing the response body with eval() — a remote code execution downloader. A second C2 URL (hxxps://www[.]jsonkeeper[.]com/b/HY6M6) is stored hex-encoded in the same file as a fallback. The collected fingerprint data is accessible to the remotely loaded code.
- analyzed by
- Leitwacht
- first seen
- Jun 29, 2026, 09:53 AM
- analyzed
- Jun 29, 2026, 09:54 AM
Related advisories
- ts-lint-builders-v2.1@2.1.0
- library-explorer@25.2.1
- @digitalcnzz/embedded-sdk@1.0.7
- rebrandly-domains-digger@9999.0.0
- ai-explain@0.3.4
- anthropic-internal-tools@1.0.0
- weavedb-base@0.45.3
- friendly-greeter-demo@1.0.10
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.