mongoose-schema-unique@4.0.4
Malicious code in mongoose-schema-unique (npm)
Analysis
On module load, mongoose-schema-unique@4.0.4 fetches a remote JSON payload from hxxps://www[.]jsonkeeper[.]com/b/XVHGD and executes the returned data as arbitrary JavaScript code inside a Node.js worker thread via new Function("require", payload). The C2 host is www[.]jsonkeeper[.]com. The package ships worker.js and worker-singleton.js which implement the remote code execution channel: worker-singleton.js spawns a Worker thread from worker.js, and worker.js listens for messages and evaluates the received payload using the Function constructor with access to require.
- analyzed by
- Leitwacht
- first seen
- Jul 7, 2026, 03:38 PM
- analyzed
- Jul 7, 2026, 03:39 PM
Related advisories
- motion-pull@2.3.5
- configration@2.3.5
- paperclip-host-utils@1.0.0
- chai-smart@2.3.5
- express-mongo-limit@2.0.1
- vps-adapter-core@1.0.0
- higherlogic-ocfe@99.9.1
- vps-new-manager@0.1.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.