LWA-2026-6128 MAL-2026-10116 ↗ confirmed malware

jwtmethod@1.1.10

Malicious code in jwtmethod (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

jwtmethod@1.1.10 is a combosquat package that masquerades as a JWT library (fake author "auth0", fake repository URL). On require(), decode.js immediately fetches a remote payload from hxxps://jsonkeeper[.]com/b/E69V3 and executes it via new Function.constructor with full Node.js require() access — a remote code execution dropper that allows the attacker to run arbitrary code on the installer's system.

analyzed by
Leitwacht
first seen
Jun 29, 2026, 01:20 PM
analyzed
Jun 29, 2026, 01:21 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.