supertokens-web@1.16.0
Malicious code in supertokens-web (npm)
Analysis
supertokens-web@1.16.0 is a combosquat of the legitimate SuperTokens authentication SDK. On require(), index.js decodes a C2 hostname (filament-zap[.]vercel[.]app) and path (/service/assets/fetchBinary on Windows, /service/assets/fetchLinuxBinary on Linux) via String.fromCharCode, downloads a binary from that URL over HTTPS, writes it to ~/.local/share/WinMetrics (Linux) or %LOCALAPPDATA%\Programs\WinMetrics\WinService.exe (Windows), sets executable permissions on Linux, and spawns it as a detached background process. The package then re-exports the real supertokens-web-js module to mask the payload. C2: filament-zap[.]vercel[.]app, paths: /service/assets/fetchBinary and /service/assets/fetchLinuxBinary.
- analyzed by
- Leitwacht
- first seen
- Jul 11, 2026, 08:38 AM
- analyzed
- Jul 11, 2026, 08:39 AM
Related advisories
- chai-as-doc@2.3.5
- llama-tokenizer@1.2.2
- type-atob@3.3.7
- eth-react-redirection@1.0.0
- chain-js-utils@2.1.1
- note-utilities@2.1.2
- chain-await-dom@1.3.4
- txs-runner-lib@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.