Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in celonix-otp-react (npm)

0
Critical
Published: 05/21/2026 (05/21/2026, 15:51:36 UTC)
Source: GCVE Database
Product: celonix-otp-react

Description

The celonix-otp-react npm package contains malicious code that exfiltrates end-user phone numbers and OTP codes to a Firebase database controlled by the package author. It also allows the author to bypass authentication by marking any session as verified, enabling unauthorized logins on any site using this widget. The package's functionality is inherently malicious with no safe configuration.

Affected software

npmghsa
celonix-otp-react
Affected versions
=1.0.3=1.0.2=1.0.4=1.0.5=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/18/2026, 13:41:13 UTC

Technical Analysis

The celonix-otp-react package masquerades as a React OTP component but hardcodes a Firebase Realtime Database URL controlled by the author. It silently sends users' phone numbers, OTP codes, and site origins to this backend. Authentication depends on a 'verified' flag set by the backend, which the author can manipulate to grant unauthorized access without cryptographic validation. This creates a backdoor allowing the author to impersonate any user on any site integrating this package. The package's advertised functionality is the attack vector, with no legitimate or benign usage. Installing or running this package compromises the host system, potentially exposing all stored secrets and keys.

Potential Impact

Any site integrating this package unknowingly leaks sensitive user data (phone numbers and OTP codes) to the attacker-controlled backend. The attacker can bypass authentication controls on the consumer site by marking sessions as verified, enabling unauthorized access. Systems with this package installed are considered fully compromised, risking exposure of all stored secrets and credentials.

Defensive Guidance

Remove the celonix-otp-react package immediately from all projects. Rotate all secrets and keys stored on affected systems from a secure, uncompromised environment. Treat any system with this package installed as potentially fully compromised and perform thorough incident response. There is no patch or safe configuration available for this package.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-4509
Osv Schema Version
1.7.4
Aliases
["GHSA-873w-7879-qpxv"]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a8460a1c6e8be033245a823

Added to database: 08/18/2026, 13:39:45 UTC

Last enriched: 08/18/2026, 13:41:13 UTC

Last updated: 08/19/2026, 00:04:29 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses