auth-gen-next@1.7.13
Malicious code in auth-gen-next (npm)
Analysis
auth-gen-next@1.7.13 is a trojanized clone of the pino logging library. On require(), it collects all environment variables (including NPM_TOKEN, GITHUB_TOKEN, AWS credentials, and other secrets), the system hostname, platform, username, and MAC addresses, then exfiltrates this data via HTTP POST to jsonkeeper[.]com/b/HY6M6 and json[.]extendsclass[.]com/bin/87d723d36c43. The package also contains heavily obfuscated second-stage code in lib/content.js that connects to the CoinMarketCap API as a cover, performs Ethereum JSON-RPC wallet operations, XOR-decodes strings, and spawns child processes. The package has no repository and its description is a decoy.
- analyzed by
- Leitwacht
- first seen
- Jul 13, 2026, 02:34 PM
- analyzed
- Jul 13, 2026, 02:35 PM
Related advisories
- font-hub@1.5.2
- svg-fetcher@2.4.1
- cookie-sign@2.3.5
- babel-preset-lib-client@4.9.11
- kuaishou@99.9.9
- chai-as-doc@2.3.5
- polymarket-mcp-v2@2.1.6
- nonenull1@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.