Malicious code in backupsitetuff6 (npm)
The npm package 'backupsitetuff6' contains malicious code that abuses the npm registry by mass-publishing nearly 100 misleading package names. It includes a browser Service Worker that serves a heavily obfuscated web proxy frontend with a popunder redirect to an external site. The package does not execute code during installation in Node environments, so the primary harm is registry namespace abuse and browser-side malicious behavior. According to one source, any system with this package installed or running should be considered fully compromised, with immediate secret/key rotation recommended.
AI Analysis
Technical Summary
The 'backupsitetuff6' npm package ships a script that republishes the same malicious payload under approximately 100 different npm package names by rewriting the package.json name and silently publishing in a loop, constituting namespace-spam abuse. The package's main entry point is a browser Service Worker that loads obfuscated proxy frontend assets and triggers a popunder redirect to 'https://abdct.com/'. No install-time hooks are declared, and requiring the package in Node fails before execution, indicating no installer-side compromise. The primary threat is abuse of the npm registry namespace and browser-side malicious proxy and redirect behavior. One source states that any computer with this package installed or running should be considered fully compromised, recommending immediate removal and secret/key rotation.
Potential Impact
The impact includes abuse of the npm registry namespace through mass publication of misleading package names, potentially confusing users and polluting the ecosystem. The browser Service Worker serves a malicious proxy frontend that redirects users to an external site via a popunder, which may lead to further malicious activity or unwanted content. Although the package does not execute code during installation in Node environments, one source warns that any system with this package installed or running may be fully compromised, implying potential post-installation compromise or persistence mechanisms not detailed here.
Mitigation Recommendations
No official patch or remediation is indicated. The package should be removed immediately if installed or running. All secrets and keys on affected systems should be rotated from a separate, trusted computer. Because the package does not execute code during installation, the main mitigation is to avoid installing or running this package and to report it for namespace abuse adjudication. Monitor npm for removal or takedown actions against these malicious packages.
Malicious code in backupsitetuff6 (npm)
Description
The npm package 'backupsitetuff6' contains malicious code that abuses the npm registry by mass-publishing nearly 100 misleading package names. It includes a browser Service Worker that serves a heavily obfuscated web proxy frontend with a popunder redirect to an external site. The package does not execute code during installation in Node environments, so the primary harm is registry namespace abuse and browser-side malicious behavior. According to one source, any system with this package installed or running should be considered fully compromised, with immediate secret/key rotation recommended.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'backupsitetuff6' npm package ships a script that republishes the same malicious payload under approximately 100 different npm package names by rewriting the package.json name and silently publishing in a loop, constituting namespace-spam abuse. The package's main entry point is a browser Service Worker that loads obfuscated proxy frontend assets and triggers a popunder redirect to 'https://abdct.com/'. No install-time hooks are declared, and requiring the package in Node fails before execution, indicating no installer-side compromise. The primary threat is abuse of the npm registry namespace and browser-side malicious proxy and redirect behavior. One source states that any computer with this package installed or running should be considered fully compromised, recommending immediate removal and secret/key rotation.
Potential Impact
The impact includes abuse of the npm registry namespace through mass publication of misleading package names, potentially confusing users and polluting the ecosystem. The browser Service Worker serves a malicious proxy frontend that redirects users to an external site via a popunder, which may lead to further malicious activity or unwanted content. Although the package does not execute code during installation in Node environments, one source warns that any system with this package installed or running may be fully compromised, implying potential post-installation compromise or persistence mechanisms not detailed here.
Mitigation Recommendations
No official patch or remediation is indicated. The package should be removed immediately if installed or running. All secrets and keys on affected systems should be rotated from a separate, trusted computer. Because the package does not execute code during installation, the main mitigation is to avoid installing or running this package and to report it for namespace abuse adjudication. Monitor npm for removal or takedown actions against these malicious packages.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10293
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-p34p-53j9-759q"]
- Ecosystems
- ["npm"]
Threat ID: 6a54add868715ace438f59b7
Added to database: 07/13/2026, 09:20:24 UTC
Last enriched: 09/12/2026, 17:32:03 UTC
Last updated: 09/12/2026, 20:38:59 UTC
Views: 43
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.