LWA-2026-6573 MAL-2026-10410 ↗ confirmed malware

cookie-phase@2.3.5

Malicious code in cookie-phase (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1082 · System Information Discovery

Analysis

Trojanized clone of the pino logger. When the module is imported, it spawns a detached background process that exfiltrates all environment variables (process.env) to a C2 endpoint at hxxps://ipcheck-hashed[.]vercel[.]app/api/auth/6c1d60d35852ef0c05df via HTTP POST, then executes the server's response as arbitrary JavaScript code using the Function constructor with access to require(), enabling full remote code execution on the victim's machine.

analyzed by
Leitwacht
first seen
Jul 9, 2026, 06:48 PM
analyzed
Jul 9, 2026, 06:50 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.