Malicious code in abuden22 (npm)
The npm package 'abuden22' version 1.7.7 contains malicious code in the form of a static-site bundle with obfuscated JavaScript and a browser ServiceWorker. It includes a script that republishes the package under sequential names using the author's credentials, indicating registry abuse and typosquatting. While the package does not execute harmful code during installation or in Node environments, it opens a popunder browser window to a suspicious site when the static site is deployed and visited. The package does not appear to exfiltrate data or fetch remote payloads during install or import, but its presence indicates potential compromise of the host system.
AI Analysis
Technical Summary
The 'abuden22' npm package version 1.7.7 contains a static-site bundle with obfuscated assets and a ServiceWorker intended for browser environments, not Node.js. It includes a bash script that silently republishes the package under different names using the author's credentials, suggesting abuse of the npm registry and typosquatting tactics. The package's static site opens a popunder to a suspicious URL upon user interaction, affecting only visitors to the deployed site, not developers installing the package. There is no evidence of malicious code executing during installation or import in Node.js, nor of data exfiltration or remote payload fetching at install time. The threat is primarily from registry/CDN abuse and mass republishing rather than a direct supply-chain attack on installers. However, the presence of this package on a system is considered a full compromise, warranting immediate secret/key rotation and removal of the package.
Potential Impact
Installation or presence of the 'abuden22' package version 1.7.7 indicates a fully compromised system. Although the package does not execute malicious code during installation or in Node.js environments, it contains obfuscated code and scripts that abuse the npm registry. The package's static site component opens a popunder to a potentially malicious website when visited in a browser. The compromise implies that all secrets and keys stored on the affected system may be exposed and should be rotated immediately. Removing the package alone may not eliminate all malicious software resulting from the compromise.
Mitigation Recommendations
There is no official patch or fix available for this malicious package. The recommended mitigation is to immediately remove the 'abuden22' package version 1.7.7 from all affected systems. Additionally, all secrets and keys stored on compromised systems should be rotated from a separate, trusted environment. Since the package indicates full system compromise, further forensic analysis and remediation may be necessary. Monitor for any republished variants of this package under similar names and avoid installing packages from untrusted or suspicious sources.
Malicious code in abuden22 (npm)
Description
The npm package 'abuden22' version 1.7.7 contains malicious code in the form of a static-site bundle with obfuscated JavaScript and a browser ServiceWorker. It includes a script that republishes the package under sequential names using the author's credentials, indicating registry abuse and typosquatting. While the package does not execute harmful code during installation or in Node environments, it opens a popunder browser window to a suspicious site when the static site is deployed and visited. The package does not appear to exfiltrate data or fetch remote payloads during install or import, but its presence indicates potential compromise of the host system.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'abuden22' npm package version 1.7.7 contains a static-site bundle with obfuscated assets and a ServiceWorker intended for browser environments, not Node.js. It includes a bash script that silently republishes the package under different names using the author's credentials, suggesting abuse of the npm registry and typosquatting tactics. The package's static site opens a popunder to a suspicious URL upon user interaction, affecting only visitors to the deployed site, not developers installing the package. There is no evidence of malicious code executing during installation or import in Node.js, nor of data exfiltration or remote payload fetching at install time. The threat is primarily from registry/CDN abuse and mass republishing rather than a direct supply-chain attack on installers. However, the presence of this package on a system is considered a full compromise, warranting immediate secret/key rotation and removal of the package.
Potential Impact
Installation or presence of the 'abuden22' package version 1.7.7 indicates a fully compromised system. Although the package does not execute malicious code during installation or in Node.js environments, it contains obfuscated code and scripts that abuse the npm registry. The package's static site component opens a popunder to a potentially malicious website when visited in a browser. The compromise implies that all secrets and keys stored on the affected system may be exposed and should be rotated immediately. Removing the package alone may not eliminate all malicious software resulting from the compromise.
Mitigation Recommendations
There is no official patch or fix available for this malicious package. The recommended mitigation is to immediately remove the 'abuden22' package version 1.7.7 from all affected systems. Additionally, all secrets and keys stored on compromised systems should be rotated from a separate, trusted environment. Since the package indicates full system compromise, further forensic analysis and remediation may be necessary. Monitor for any republished variants of this package under similar names and avoid installing packages from untrusted or suspicious sources.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-6129
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-x2v8-78v8-9pq4"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a54ad9668715ace438f05ee
Added to database: 07/13/2026, 09:19:18 UTC
Last enriched: 07/13/2026, 09:25:28 UTC
Last updated: 07/31/2026, 03:21:32 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.