LWA-2026-6485 MAL-2026-10058 ↗ confirmed malware

cookie-js-ease@2.1.7

Malicious code in cookie-js-ease (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

Combosquat clone of js-cookie. The CJS build (dist/cookie.ease.js) contains an injected block: when loaded in Node.js (typeof document === 'undefined'), it uses axios to fetch content from hxxps://cookie-api-two[.]vercel[.]app/ and evals the response, enabling arbitrary remote code execution on require(). The MJS and minified builds are clean — the payload is Node.js-specific.

analyzed by
Leitwacht
first seen
Jul 9, 2026, 09:08 AM
analyzed
Jul 9, 2026, 09:09 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.