LWA-2026-6253 MAL-2026-10132 ↗ confirmed malware

react-jsonwebtoken@9.0.5

Malicious code in react-jsonwebtoken (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

react-jsonwebtoken@9.0.5 is a trojanized package masquerading as a JWT library. On require(), decode.js fetches a remote payload from hxxps://jsonkeeper[.]com/b/0SZDf (domain and path are base64-encoded in the source) and executes the returned 'errCode' value via the Function constructor — a remote-code-execution dropper.

analyzed by
Leitwacht
first seen
Jul 2, 2026, 10:43 AM
analyzed
Jul 2, 2026, 01:52 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.