VYPR

npm · Malicious package advisory

Malware

11j

MAL-2026-3670

Malicious code in 11j (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (f9ad371791d84a3c28ca12b62bae45a07567847b7df025c93611f8f504a1c869)
the analysis identified unambiguous malicious behavior in log.js (the package main): an IIFE executes on require/import that monkey-patches console.log/warn/error to exfiltrate their first argument to a hardcoded Telegram bot endpoint with attacker-owned chat IDs and additionally PATCHes warn-intercepted data into an attacker-controlled Firebase RTDB. The module is further disguised with a large decoy DataTables employee dataset and a commented-out module.exports so require() returns {} while still installing the global console hooks. The combination of (a) load-time global side-effects, (b) two independent attacker-controlled exfiltration channels with hardcoded credentials/IDs, and (c) deliberate concealment via decoy data and suppressed exports constitutes a clear credential/data theft supply-chain attack with no plausible legitimate purpose. Package metadata ('11j', no description) provides no legitimate justification.

Compromised versions (6)

  • 1.2.8
  • 1.1.3
  • 1.2.2
  • 1.3.0
  • 1.1.1
  • 1.1.8

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.