db-query-log@1.0.2
Malicious code in db-query-log (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or InformationT1105 · Ingress Tool Transfer
Analysis
db-query-log@1.0.2 is a trojanized database-connector library that contains a remote code execution downloader. The queryDBConnect() method in index.js base64-decodes a URL pointing to jsonkeeper[.]com, fetches the hosted content via axios, and compiles it as a live Node.js module using Module._compile(), allowing the remote server to execute arbitrary code in the installer's process. The package has no repository, and the downloader is embedded inside an otherwise legitimate-looking database connector class.
- analyzed by
- Leitwacht
- first seen
- Jul 2, 2026, 03:30 PM
- analyzed
- Jul 2, 2026, 03:31 PM
Related advisories
- @marketfront/fingerprint@7.0.0
- @marketfront/basemarkettemplate@7.0.0
- @marketfront/bannerpopup@7.0.0
- hardhat-plugin-solidity@2.3.1
- lessload@1.0.1
- @digitalcnzz/embedded-sdk@1.0.7
- @immobiliarelabs/backstage-plugin-ldap-auth-backend@1.1.3
- autotel-edge@3.16.13
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.