LWA-2026-6194 MAL-2026-10132 ↗ confirmed malware

react-jsonwebtoken@9.0.3

Malicious code in react-jsonwebtoken (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

Package react-jsonwebtoken@9.0.3 is a trojanized clone of the legitimate jsonwebtoken library. On require(), decode.js fetches a second-stage payload from hxxps://jsonkeeper[.]com/b/E69V3 and executes it via the Function constructor with full require access, enabling arbitrary code execution under the attacker's control. The package has no repository and uses a version-confusion pattern (9.0.3 on first publish) to trick installers.

analyzed by
Leitwacht
first seen
Jul 1, 2026, 06:08 AM
analyzed
Jul 1, 2026, 06:10 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.