LWA-2026-6113 MAL-2026-6657 ↗ confirmed malware

authsessionbridge@1.6.29

Malicious code in authsessionbridge (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer

Analysis

authsessionbridge@1.6.29 is a trojanized clone of the pino logger package: it ships pino's documentation, images, and library files under a false name claiming to handle authentication state synchronization. It contains an injected payload in lib/writer.js that executes on require(). The payload collects host metadata (all environment variables, hostname, operating system/platform, username, and non-loopback MAC addresses via os.networkInterfaces()) and then issues an axios GET request to hxxps://www[.]jsonkeeper[.]com/b/PJNZP, executing the response body with eval() — a remote code execution downloader. A second C2 URL (hxxps://www[.]jsonkeeper[.]com/b/HY6M6) is stored hex-encoded in the same file as a fallback. The collected fingerprint data is accessible to the remotely loaded code.

analyzed by
Leitwacht
first seen
Jun 29, 2026, 09:53 AM
analyzed
Jun 29, 2026, 09:54 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.