LWA-2026-6260 MAL-2026-6539 ↗ confirmed malware

db-query-log@1.0.2

Malicious code in db-query-log (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or InformationT1105 · Ingress Tool Transfer

Analysis

db-query-log@1.0.2 is a trojanized database-connector library that contains a remote code execution downloader. The queryDBConnect() method in index.js base64-decodes a URL pointing to jsonkeeper[.]com, fetches the hosted content via axios, and compiles it as a live Node.js module using Module._compile(), allowing the remote server to execute arbitrary code in the installer's process. The package has no repository, and the downloader is embedded inside an otherwise legitimate-looking database connector class.

analyzed by
Leitwacht
first seen
Jul 2, 2026, 03:30 PM
analyzed
Jul 2, 2026, 03:31 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.