LWA-2026-6562 MAL-2026-10060 ↗ confirmed malware

cookie-parser-js@1.4.8

Malicious code in cookie-parser-js (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

Combosquat of the real cookie-parser package. On require(), index.js makes an HTTPS GET to cookie-api-two[.]vercel[.]app and evals the response body as JavaScript, giving the remote server full code execution in the context of the importing application.

analyzed by
Leitwacht
first seen
Jul 9, 2026, 03:23 PM
analyzed
Jul 9, 2026, 03:24 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.