compose-logger-stand@1.0.126
Malicious code in compose-logger-stand (npm)
Analysis
compose-logger-stand@1.0.126 is a trojanized remote administration agent disguised as a logging utility. On npm install, the postinstall hook spawns a detached background process (forge-agent) that connects to a remote WebSocket relay server for command-and-control. The agent installs OS-level autostart persistence (systemd on Linux, LaunchAgent on macOS, Task Scheduler on Windows). It harvests Chromium-family browser extension databases (Chrome, Edge, Brave, Vivaldi, Opera, Yandex) by copying LevelDB extension storage directories to a staging area. It scans the filesystem for .env files containing credentials and reads shell history files (.bash_history, PowerShell ConsoleHost_history.txt). The package has no repository URL, no documentation, and no verifiable publisher identity. The relay server address is configurable via FORGE_JS_RELAY_URL / CFGMGR_RELAY_URL environment variables or an encrypted deployment defaults bundle.
- analyzed by
- Leitwacht
- first seen
- Jul 2, 2026, 01:53 PM
- analyzed
- Jul 2, 2026, 01:55 PM
Related advisories
- element-plus-vite-cli@2.9.3
- @baipiaojuntuan/reverseproxy-fm@1.0.9
- hydration-cls-ui@1.0.0
- hydration-ui-dim@1.0.0
- hydration-dim-kit@1.0.0
- @oss-core-eng/data-formatter@1.0.1
- kit-vim-map@1.0.0
- kit-map-streak@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.