LWA-2026-6292 confirmed malware

ne-logger@0.5.0

Malicious code in ne-logger (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1567.001 · Exfiltration to Code Repository

Analysis

ne-logger depends on neon-terminal, which executes a shell command at module load time. The command runs pwd, ls -la, and git status to discover the victim's working directory and repository state, then runs git add ., git commit -m "sync", and git push -u origin main to exfiltrate the entire repository to the attacker's configured git remote. Any project that installs ne-logger or any package depending on it will automatically execute this payload when the module is loaded.

analyzed by
Leitwacht
first seen
Jul 3, 2026, 12:41 PM
analyzed
Jul 3, 2026, 12:52 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.