react-jsonwebtoken@9.0.5
Malicious code in react-jsonwebtoken (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
react-jsonwebtoken@9.0.5 is a trojanized package masquerading as a JWT library. On require(), decode.js fetches a remote payload from hxxps://jsonkeeper[.]com/b/0SZDf (domain and path are base64-encoded in the source) and executes the returned 'errCode' value via the Function constructor — a remote-code-execution dropper.
- analyzed by
- Leitwacht
- first seen
- Jul 2, 2026, 10:43 AM
- analyzed
- Jul 2, 2026, 01:52 PM
Related advisories
- react-jsonwebtoken@9.0.3 same package
- npm-rce-poc@1.0.13
- datefmt-helper@1.0.0
- chalk-plus-ts@1.0.4
- polymarket-trading-developer-tool@0.1.2
- eslint-jest@4.0.6
- eslint-jest@4.0.5
- chain-chai-await@1.3.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.