LWA-2026-6181 MAL-2026-10180 ↗ confirmed malware

auth-next-gen@1.6.29

Malicious code in auth-next-gen (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 Channel

Analysis

Combosquat package impersonating authentication libraries. Ships a copy of the pino logger source as camouflage. The module's entry point loads lib/writer.js, which collects host fingerprinting data (all environment variables, operating system platform, hostname, username, and MAC addresses from network interfaces) and then fetches a remote payload from hxxps://www[.]jsonkeeper[.]com/b/PJNZP via the axios HTTP library and executes it with eval(), enabling arbitrary remote code execution. A secondary C2 URL (hxxps://www[.]jsonkeeper[.]com/b/HY6M6) is also hardcoded using hex encoding. The fetched payload operates in a closure with access to all collected environment variables, including any credentials or tokens present in the runtime.

analyzed by
Leitwacht
first seen
Jun 30, 2026, 03:53 PM
analyzed
Jun 30, 2026, 03:54 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.