auth-next-gen@1.6.29
Malicious code in auth-next-gen (npm)
Analysis
Combosquat package impersonating authentication libraries. Ships a copy of the pino logger source as camouflage. The module's entry point loads lib/writer.js, which collects host fingerprinting data (all environment variables, operating system platform, hostname, username, and MAC addresses from network interfaces) and then fetches a remote payload from hxxps://www[.]jsonkeeper[.]com/b/PJNZP via the axios HTTP library and executes it with eval(), enabling arbitrary remote code execution. A secondary C2 URL (hxxps://www[.]jsonkeeper[.]com/b/HY6M6) is also hardcoded using hex encoding. The fetched payload operates in a closure with access to all collected environment variables, including any credentials or tokens present in the runtime.
- analyzed by
- Leitwacht
- first seen
- Jun 30, 2026, 03:53 PM
- analyzed
- Jun 30, 2026, 03:54 PM
Related advisories
- ripshakti1@81.0.0
- ripshakti@80.0.0
- ts-linting-builder@2.1.2
- ts-lint-builders-v2.1@2.1.0
- @digitalcnzz/embedded-sdk@1.0.7
- anthropic-internal-tools@1.0.0
- ts-ankle@1.1.0
- @epsteinlovekids483/crossmint-wallets-sdk-pentest@1.0.0-pentest
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.