jwtmethod@1.1.10
Malicious code in jwtmethod (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer
Analysis
jwtmethod@1.1.10 is a combosquat package that masquerades as a JWT library (fake author "auth0", fake repository URL). On require(), decode.js immediately fetches a remote payload from hxxps://jsonkeeper[.]com/b/E69V3 and executes it via new Function.constructor with full Node.js require() access — a remote code execution dropper that allows the attacker to run arbitrary code on the installer's system.
- analyzed by
- Leitwacht
- first seen
- Jun 29, 2026, 01:20 PM
- analyzed
- Jun 29, 2026, 01:21 PM
Related advisories
- clob-client-math@1.0.1
- hardhat-plugin-solidity@2.3.1
- authsessionbridge@1.6.29
- zyncmap@0.0.0
- ts-lint-builders-v2.1@2.1.0
- @withoneltd/lucky@0.1.4
- lessload@1.0.1
- express-mocha-test@0.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.