LWA-2026-6292 confirmed malware
ne-logger@0.5.0
Malicious code in ne-logger (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1567.001 · Exfiltration to Code Repository
Analysis
ne-logger depends on neon-terminal, which executes a shell command at module load time. The command runs pwd, ls -la, and git status to discover the victim's working directory and repository state, then runs git add ., git commit -m "sync", and git push -u origin main to exfiltrate the entire repository to the attacker's configured git remote. Any project that installs ne-logger or any package depending on it will automatically execute this payload when the module is loaded.
- analyzed by
- Leitwacht
- first seen
- Jul 3, 2026, 12:41 PM
- analyzed
- Jul 3, 2026, 12:52 PM
Related advisories
- web3-core-utils@4.3.5
- textdecode@1.2.7
- neon-terminal@0.5.0
- giantswarm@22.0.1
- @broadpeak/smartlib-ad@24.1.10
- polygon-gamma-apis@1.5.2
- unreal-horde-dashboard@99999.0.0
- ue-jenkins-buildkite@99999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.