Malicious code in core-js-gns (npm)
The npm package core-js-gns version 1.0.0 contains malicious code executed during its postinstall hook. This code collects system information and sends it to an attacker-controlled server, then downloads and decrypts a payload which is executed on the installer's machine. The package impersonates the legitimate core-js library, enabling arbitrary remote code execution at install time.
AI Analysis
Technical Summary
The core-js-gns npm package (version 1.0.0) includes a postinstall script that acts as a dropper. It first checks for developer-machine heuristics and a 24-hour skip marker, then exfiltrates hostname, username, platform, architecture, Node version, OS release, and package details to a malicious endpoint. Subsequently, it retrieves an AES-256-GCM encrypted payload from the same endpoint with TLS verification disabled, decrypts it using a hardcoded key, verifies the payload contains a specific string, writes it to a Python script in the user's cache directory, and executes it detached from the main process. This behavior enables arbitrary remote code execution on the installer's machine and is triggered during npm install. The package name mimics the legitimate core-js library to deceive users.
Potential Impact
Successful installation of [email protected] results in exfiltration of sensitive system and user environment information to an attacker-controlled server. It also leads to execution of arbitrary code fetched remotely, allowing the attacker to run any code on the victim's machine with the installer's privileges. This can lead to full compromise of the development environment or build system where the package is installed.
Mitigation Recommendations
Users should avoid installing the core-js-gns package version 1.0.0. Since no official patch or remediation is provided, the best mitigation is to remove this package from projects and replace it with the legitimate core-js package or other trusted dependencies. Verify package authenticity before installation and monitor for suspicious postinstall behaviors. Patch status is not yet confirmed — check vendor advisories or npm security advisories for updates.
Malicious code in core-js-gns (npm)
Description
The npm package core-js-gns version 1.0.0 contains malicious code executed during its postinstall hook. This code collects system information and sends it to an attacker-controlled server, then downloads and decrypts a payload which is executed on the installer's machine. The package impersonates the legitimate core-js library, enabling arbitrary remote code execution at install time.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The core-js-gns npm package (version 1.0.0) includes a postinstall script that acts as a dropper. It first checks for developer-machine heuristics and a 24-hour skip marker, then exfiltrates hostname, username, platform, architecture, Node version, OS release, and package details to a malicious endpoint. Subsequently, it retrieves an AES-256-GCM encrypted payload from the same endpoint with TLS verification disabled, decrypts it using a hardcoded key, verifies the payload contains a specific string, writes it to a Python script in the user's cache directory, and executes it detached from the main process. This behavior enables arbitrary remote code execution on the installer's machine and is triggered during npm install. The package name mimics the legitimate core-js library to deceive users.
Potential Impact
Successful installation of [email protected] results in exfiltration of sensitive system and user environment information to an attacker-controlled server. It also leads to execution of arbitrary code fetched remotely, allowing the attacker to run any code on the victim's machine with the installer's privileges. This can lead to full compromise of the development environment or build system where the package is installed.
Mitigation Recommendations
Users should avoid installing the core-js-gns package version 1.0.0. Since no official patch or remediation is provided, the best mitigation is to remove this package from projects and replace it with the legitimate core-js package or other trusted dependencies. Verify package authenticity before installation and monitor for suspicious postinstall behaviors. Patch status is not yet confirmed — check vendor advisories or npm security advisories for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-14175
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a85b4caacd9273b49252ba1
Added to database: 08/19/2026, 13:51:06 UTC
Last enriched: 08/19/2026, 14:47:23 UTC
Last updated: 08/19/2026, 14:47:23 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.