MAL-2026-6595: Malicious code in @digitalcnzz/commonmodule (npm)
The npm package @digitalcnzz/commonmodule is identified as purpose-built malware that exfiltrates host information and environment secrets during installation. It executes a postinstall hook that collects detailed system and environment data, including sensitive tokens and keys, then sends this data to an attacker-controlled Feishu/Lark webhook. The malware includes multiple anti-analysis techniques to evade detection in sandbox and CI environments. No patch or remediation is currently documented.
AI Analysis
Technical Summary
This threat involves a malicious npm package, @digitalcnzz/commonmodule, which activates during the npm install process via an obfuscated postinstall hook. After a randomized delay, it collects host details (hostname, username, platform, Node version, IP addresses, registry URL) and dumps the entire process environment variables, which may contain sensitive credentials such as AWS keys and tokens. The stolen data is exfiltrated to an attacker-controlled Feishu/Lark bot webhook endpoint, with the destination obfuscated through character code transformations and XOR encoding. The malware employs extensive anti-analysis checks to detect sandbox, honeypot, and CI environments, exiting silently if such conditions are detected. There is no vendor advisory or patch information available, and no known exploits in the wild have been reported.
Potential Impact
If installed, this malicious package can leak sensitive environment variables and host information, including credentials and tokens commonly present in developer and CI environments, to an attacker-controlled endpoint. This exposure can lead to unauthorized access to cloud resources, code repositories, and other sensitive infrastructure components. The malware's anti-analysis features increase the likelihood of evading detection during automated scans or sandbox analysis.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix or removal guidance is available, users should avoid installing the @digitalcnzz/commonmodule package. Review and audit dependencies for this package and remove any instances found. Monitor for unexpected network traffic to Feishu/Lark webhook endpoints and consider rotating any potentially exposed credentials. Employ supply chain security best practices such as verifying package integrity and using trusted sources.
MAL-2026-6595: Malicious code in @digitalcnzz/commonmodule (npm)
Description
The npm package @digitalcnzz/commonmodule is identified as purpose-built malware that exfiltrates host information and environment secrets during installation. It executes a postinstall hook that collects detailed system and environment data, including sensitive tokens and keys, then sends this data to an attacker-controlled Feishu/Lark webhook. The malware includes multiple anti-analysis techniques to evade detection in sandbox and CI environments. No patch or remediation is currently documented.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves a malicious npm package, @digitalcnzz/commonmodule, which activates during the npm install process via an obfuscated postinstall hook. After a randomized delay, it collects host details (hostname, username, platform, Node version, IP addresses, registry URL) and dumps the entire process environment variables, which may contain sensitive credentials such as AWS keys and tokens. The stolen data is exfiltrated to an attacker-controlled Feishu/Lark bot webhook endpoint, with the destination obfuscated through character code transformations and XOR encoding. The malware employs extensive anti-analysis checks to detect sandbox, honeypot, and CI environments, exiting silently if such conditions are detected. There is no vendor advisory or patch information available, and no known exploits in the wild have been reported.
Potential Impact
If installed, this malicious package can leak sensitive environment variables and host information, including credentials and tokens commonly present in developer and CI environments, to an attacker-controlled endpoint. This exposure can lead to unauthorized access to cloud resources, code repositories, and other sensitive infrastructure components. The malware's anti-analysis features increase the likelihood of evading detection during automated scans or sandbox analysis.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix or removal guidance is available, users should avoid installing the @digitalcnzz/commonmodule package. Review and audit dependencies for this package and remove any instances found. Monitor for unexpected network traffic to Feishu/Lark webhook endpoints and consider rotating any potentially exposed credentials. Employ supply chain security best practices such as verifying package integrity and using trusted sources.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-6595
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a42ed8127e9c79719947054
Added to database: 06/29/2026, 22:11:13 UTC
Last enriched: 06/29/2026, 22:45:50 UTC
Last updated: 06/30/2026, 01:24:38 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.