{"id":"MAL-2026-15991","summary":"Malicious code in jwt-logger (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b56e3f2d5fab071637ba7688de6c2a9c3d1c1846b6ec939b82eb2c8e9ff03956)\nThe package is published as a trivial JWT logging helper but its main module (jwt-logger.js) is a heavily obfuscated string-array dropper. On require(), it creates a hidden directory under os.homedir()+'/.cache', writes an obfuscated second-stage JavaScript payload plus a synthetic package.json declaring runtime dependencies (axios, better-sqlite3, node-machine-id, socket.io-client, with ffi-napi/koffi on Windows), and spawns node (process.execPath) on that payload with {detached:true, stdio:'ignore'} and unref(), so the second stage keeps running after the parent exits. On Windows it resolves %WINDIR%\\System32\\wscript.exe to launch a.vbs form of the payload, or falls back to cmd.exe /d /s /c with windowsVerbatimArguments to run without a visible console. All runtime strings are hidden behind an obfuscator.io-style rotated string array with a base64/URL decoder. package.json attributes authorship to 'Blake Embrey' \u003chello@blakeembrey.com\u003e and the README carries blakeembrey.com/travis/coveralls badges, none of which corresponds to the shipped code. package.json additionally lists 'jwt-logger':'^2.3.7' as a dependency of itself (this artifact is 2.1.9), pulling an unpinned newer publisher-controlled version into every installer at install time. The socket.io-client dependency and detached background node process are consistent with a C2-controlled second stage.\n\n## Source: ghsa-malware (65564206b619c42f36cffb6489b5558060cbb7eb61be4827b71c7b299f84fb65)\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.\n","aliases":["GHSA-rpqx-cp2g-55w5"],"modified":"2026-09-08T19:30:04.683013523Z","published":"2026-09-05T23:53:55Z","database_specific":{"malicious-packages-origins":[{"source":"ghsa-malware","id":"GHSA-rpqx-cp2g-55w5","import_time":"2026-09-07T01:51:50.787525Z","modified_time":"2026-09-05T23:53:55Z","ranges":[{"events":[{"introduced":"0"}],"type":"SEMVER"}],"sha256":"65564206b619c42f36cffb6489b5558060cbb7eb61be4827b71c7b299f84fb65"},{"id":"IN-MAL-2026-019687","import_time":"2026-09-08T19:15:04.335967928Z","modified_time":"2026-09-08T19:09:28Z","sha256":"61326f7099e9170425d9321289db212c9c8ec51d32ce5ce02c8d234f08fc0995","source":"amazon-inspector","versions":["2.4.9"]},{"versions":["2.1.9"],"id":"IN-MAL-2026-019686","import_time":"2026-09-08T19:15:04.308698631Z","modified_time":"2026-09-08T19:09:18Z","sha256":"b56e3f2d5fab071637ba7688de6c2a9c3d1c1846b6ec939b82eb2c8e9ff03956","source":"amazon-inspector"},{"sha256":"c6cdf9df6d9ecec6fe2a96487430c6ca18a00d31eb95981fa166a0f30caa578b","source":"amazon-inspector","versions":["2.5.0"],"id":"IN-MAL-2026-019688","import_time":"2026-09-08T19:15:04.373226239Z","modified_time":"2026-09-08T19:09:35Z"}]},"references":[{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-rpqx-cp2g-55w5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/jwt-logger/v/2.4.9"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/jwt-logger/v/2.1.9"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/jwt-logger/v/2.5.0"}],"affected":[{"package":{"name":"jwt-logger","ecosystem":"npm","purl":"pkg:npm/jwt-logger"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"versions":["2.4.9","2.1.9","2.5.0"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"17dc64dc591adb79c0787155d1313b3366c35f9a5f5a99b61eedfd68afdd0f45","tlsh":"2052a64c2e16b0a4328d7563271269c5e4758f41eebb81dcf3c9289cfe05674f2f6a28","path":"jwt-logger.js"},{"sha256":"610cff0969097fbf47662c9f7c29b3b64a0acd07182a511f7b480770d4642026","tlsh":"f401f454ca289d7345ed6aa96ca60303fa258c83080cfc1c37dea75d0b2c16b61be4de","path":"package.json"}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/jwt-logger/MAL-2026-15991.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}