cookie-phase@2.3.5
Malicious code in cookie-phase (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1082 · System Information Discovery
Analysis
Trojanized clone of the pino logger. When the module is imported, it spawns a detached background process that exfiltrates all environment variables (process.env) to a C2 endpoint at hxxps://ipcheck-hashed[.]vercel[.]app/api/auth/6c1d60d35852ef0c05df via HTTP POST, then executes the server's response as arbitrary JavaScript code using the Function constructor with access to require(), enabling full remote code execution on the victim's machine.
- analyzed by
- Leitwacht
- first seen
- Jul 9, 2026, 06:48 PM
- analyzed
- Jul 9, 2026, 06:50 PM
Related advisories
- polymarket-mcp-v2@2.1.6
- chunk-parser@1.0.0
- nonenull1@1.0.0
- es6-codify@2.2.0
- chai-as-smart@2.3.5
- @wagni_bot/meteora-sdk@1.2.0
- @wagni_bot/ethereum-wallet@1.0.0
- @wagni_bot/solana-sdk@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.