MAL-2026-3670

    Dashboard / Malicious Package / MAL-2026-3670

    MAL-2026-3670

    Published: 12 May 2026Last Modified: 13 May 2026

    Summary: Malicious code in 11j (npm)

    Details: Source: amazon-inspector (f9ad371791d84a3c28ca12b62bae45a07567847b7df025c93611f8f504a1c869) the analysis identified unambiguous malicious behavior in log.js (the package main): an IIFE executes on require/import that monkey-patches console.log/warn/error to exfiltrate their first argument to a hardcoded Telegram bot endpoint with attacker-owned chat IDs and additionally PATCHes warn-intercepted data into an attacker-controlled Firebase RTDB. The module is further disguised with a large decoy DataTables employee dataset and a commented-out module.exports so require() returns {} while still installing the global console hooks. The combination of (a) load-time global side-effects, (b) two independent attacker-controlled exfiltration channels with hardcoded credentials/IDs, and (c) deliberate concealment via decoy data and suppressed exports constitutes a clear credential/data theft supply-chain attack with no plausible legitimate purpose. Package metadata ('11j', no description) provides no legitimate justification.

    Affected packages

    Package

    Name: 11j

    Purl: pkg:npm/11j

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.2.8
    1.2.2