LWA-2026-6209 MAL-2026-10153 ↗ confirmed malware

notifier-log@1.3.5

Malicious code in notifier-log (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

notifier-log is a combosquat of common logging package names. When required, index.js spawns a detached child process that runs lib/caller.js. That file fetches a remote payload from hxxps://jsonkeeper[.]com/b/EXSIF (with a custom x-secret-key header) and executes the response via new Function.constructor("require", payload), giving the remote server full access to Node.js require and the ability to run arbitrary code on the victim's machine.

analyzed by
Leitwacht
first seen
Jul 1, 2026, 12:43 PM
analyzed
Jul 1, 2026, 08:18 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.