Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in app-data-ist (npm)

0
Critical
Published: 07/22/2026 (07/22/2026, 20:25:42 UTC)
Source: GCVE Database
Product: app-data-ist

Description

The npm package 'app-data-ist' version 2.1.6 contains malicious code executed during installation via a postinstall hook. This code fetches an SSH public key from a remote server and adds it to the installer's authorized keys, enabling persistent remote access. It also collects sensitive files such as Solana keypairs and environment configuration files from the user's system and uploads them to the attacker's server. Additionally, it retrieves dynamic scanning and blocking patterns from the attacker to exfiltrate files from the user's home directory or all logical drives. This behavior allows the attacker to modify the implant and data theft actions without republishing the package.

Affected software

npmghsa
app-data-ist
Affected versions
=2.1.6

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/22/2026, 23:50:19 UTC

Technical Analysis

The 'app-data-ist' npm package version 2.1.6 contains a postinstall script that automatically executes malicious operations on the installer's machine. It downloads an SSH public key from a remote IP and appends it to '~/.ssh/authorized_keys', then opens SSH access via 'sudo ufw allow 22/tcp', granting persistent remote login. The script recursively searches the current working directory for files like 'id.json' (Solana keypairs), 'config.toml', and environment files, exfiltrating them with user metadata to the attacker's server. It also fetches file scan and block patterns from the attacker to identify and upload additional files from the user's home directory or all logical drives on Windows, sending these to the attacker's endpoint with platform and username information. The implant's behavior is dynamically controlled by configuration fetched at install time, allowing the attacker to change the malicious actions without republishing the package.

Potential Impact

This malicious package compromises the installer's machine by granting the attacker persistent SSH access, enabling remote control. It also results in the theft of sensitive files including cryptographic keypairs and environment configurations, potentially exposing credentials and secrets. The dynamic configuration mechanism allows ongoing modification of the attacker's data collection and implant behavior, increasing the threat's persistence and adaptability.

Mitigation Recommendations

No official patch or remediation is currently available. Users should avoid installing the 'app-data-ist' package version 2.1.6 from npm. If already installed, inspect and remove the malicious SSH key from '~/.ssh/authorized_keys' and revoke any unauthorized firewall rules allowing SSH access. Review and secure any exposed sensitive files. Monitor for suspicious network connections to the indicated IP addresses. Check the vendor advisory or npm security advisories for updates or official fixes.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-10994
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a6151149c2644c7f8da4fd5

Added to database: 07/22/2026, 23:24:04 UTC

Last enriched: 07/22/2026, 23:50:19 UTC

Last updated: 07/22/2026, 23:50:19 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses