Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in caldora (npm)

0
High
Published: 08/05/2026 (08/05/2026, 12:55:53 UTC)
Source: GCVE Database
Product: caldora

Description

The npm package caldora version 1.0.0 contains malicious code that executes on import when run in a Linux environment with the Windows Subsystem for Linux (WSL) present and NODE_ENV not set to 'production'. It downloads a binary from a third-party file host and writes it as 'vite-native-helper.exe' into the Windows user's Startup folder, enabling persistent execution on the Windows host at next login. The payload is obfuscated by splitting the URL into parts and is dormant in typical developer or CI environments, targeting WSL developer hosts specifically. The package's declared functionality does not require this native helper, indicating malicious intent.

Affected software

npmghsa
caldora
Affected versions
=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/05/2026, 17:21:22 UTC

Technical Analysis

The caldora npm package version 1.0.0 runs a top-level asynchronous routine on import that, under specific conditions (Linux with /mnt/c present indicating WSL, and NODE_ENV not 'production'), constructs a URL from split strings to download a binary file named 'vite-native-helper.exe' from a third-party host (f004.backblazeb2.com). This binary is then written into the Windows Startup folder of the host user, ensuring it runs automatically on the next Windows login. This behavior establishes persistent code execution on the Windows host originating from a WSL-based install. The obfuscation and environment checks are designed to evade detection on typical developer machines and continuous integration systems. The malicious executable masquerades as a legitimate vite helper, although the package does not require any native helper, confirming the malicious nature of the payload.

Potential Impact

This malicious package enables persistent unauthorized code execution on Windows hosts via WSL by dropping and executing a binary at user login. This persistence mechanism can allow attackers to maintain foothold on affected systems, potentially leading to further compromise. The payload is specifically targeted to WSL environments with non-production NODE_ENV settings, reducing detection likelihood in standard environments.

Mitigation Recommendations

No official patch or remediation is currently documented. Users should avoid installing or using caldora version 1.0.0. If already installed in a WSL environment, users should check for and remove the 'vite-native-helper.exe' file from the Windows Startup folder to prevent persistent execution. Monitor for suspicious activity related to this executable. Patch status is not yet confirmed — check the vendor advisory or trusted security sources for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-12344
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a735744bf8831d539159cb1

Added to database: 08/05/2026, 15:31:16 UTC

Last enriched: 08/05/2026, 17:21:22 UTC

Last updated: 08/05/2026, 17:21:22 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses