MAL-2026-3670
Dashboard / Malicious Package / MAL-2026-3670
MAL-2026-3670
Summary: Malicious code in 11j (npm)
Details: Source: amazon-inspector (f9ad371791d84a3c28ca12b62bae45a07567847b7df025c93611f8f504a1c869) the analysis identified unambiguous malicious behavior in log.js (the package main): an IIFE executes on require/import that monkey-patches console.log/warn/error to exfiltrate their first argument to a hardcoded Telegram bot endpoint with attacker-owned chat IDs and additionally PATCHes warn-intercepted data into an attacker-controlled Firebase RTDB. The module is further disguised with a large decoy DataTables employee dataset and a commented-out module.exports so require() returns {} while still installing the global console hooks. The combination of (a) load-time global side-effects, (b) two independent attacker-controlled exfiltration channels with hardcoded credentials/IDs, and (c) deliberate concealment via decoy data and suppressed exports constitutes a clear credential/data theft supply-chain attack with no plausible legitimate purpose. Package metadata ('11j', no description) provides no legitimate justification.
References: https://www.npmjs.com/package/11j/v/1.2.8, https://www.npmjs.com/package/11j/v/1.1.3, https://www.npmjs.com/package/11j/v/1.2.2, https://www.npmjs.com/package/11j/v/1.3.0, https://www.npmjs.com/package/11j/v/1.1.1, https://www.npmjs.com/package/11j/v/1.1.8
Affected packages
Package
Name: 11j
Purl: pkg:npm/11j
Affected ranges
Type: N/A
Events:
