compose-logger-stand@1.0.126
Malicious code in compose-logger-stand (npm)
Analysis
compose-logger-stand@1.0.126 is a trojanized remote administration agent disguised as a logging utility. On npm install, the postinstall hook spawns a detached background process (forge-agent) that connects to a remote WebSocket relay server for command-and-control. The agent installs OS-level autostart persistence (systemd on Linux, LaunchAgent on macOS, Task Scheduler on Windows). It harvests Chromium-family browser extension databases (Chrome, Edge, Brave, Vivaldi, Opera, Yandex) by copying LevelDB extension storage directories to a staging area. It scans the filesystem for .env files containing credentials and reads shell history files (.bash_history, PowerShell ConsoleHost_history.txt). The package has no repository URL, no documentation, and no verifiable publisher identity. The relay server address is configurable via FORGE_JS_RELAY_URL / CFGMGR_RELAY_URL environment variables or an encrypted deployment defaults bundle.
- analyzed by
- Leitwacht
- first seen
- Jul 2, 2026, 01:53 PM
- analyzed
- Jul 2, 2026, 01:55 PM
Related advisories
- streak-kit-map@1.0.0
- streak-map-cache@1.0.0
- streak-cache-map@1.0.0
- @lizhao1/memorax-code-internal@0.1.2
- streak-calc-math@1.0.0
- streak-math-calc@1.0.0
- shadxino@1.0.7
- string-utils-kit@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.