Malicious code in @nestjs-passport/jwt (npm)
MAL-2026-13627
Published · Modified
Description
__
Source: amazon-inspector (0d3060c9289c475e223c1c00bc21a0f59f8aa5b18e31bfaee6e4d923eab0042f)
Package published under the @nestjs-passport scope, which resembles the official @nestjs/jwt and @nestjs/passport packages. The sole entrypoint files dist/index.cjs and dist/index.js each consist of a single-line JSFuck-encoded string (~2.3MB of permutations of!+[],!![], +[]) that is passed to new Function('jose',
Ready to move
Start Securing
Free, no credit card | First findings in minutes