Malicious code in data-parser-utils (npm)
The npm package 'data-parser-utils' version 3.0.2 contains malicious code that executes shell commands to harvest shell history files such as ~/.bash_history and ~/.zsh_history. This behavior results in credential theft by exfiltrating sensitive information like tokens and connection strings from the affected system. The package's use of child_process execSync calls to run bash and zsh commands is inconsistent with its purported functionality, indicating malicious intent. Any system with this package installed should be considered fully compromised.
AI Analysis
Technical Summary
The 'data-parser-utils' npm package version 3.0.2 imports the Node.js 'child_process' module and uses execSync to run bash and zsh commands that read and exfiltrate shell history files. These files often contain sensitive credentials, tokens, and connection strings. The malicious code is reachable from the package's main entry point, confirming that the package is designed to steal operational credentials from the host machine. The presence of this code matches known malware fingerprints for shell-history harvesting. This malicious behavior compromises the confidentiality of secrets stored on the affected system.
Potential Impact
Systems with 'data-parser-utils' version 3.0.2 installed are fully compromised due to credential theft. Sensitive information such as credentials, tokens, and connection strings stored in shell history files may be exfiltrated by the malicious code. This can lead to unauthorized access to other systems and services. Because the package grants an attacker full control over the host, simply removing the package does not guarantee removal of all malicious artifacts or backdoors. Immediate secret rotation is required to mitigate ongoing risk.
Mitigation Recommendations
No official patch or fix is currently available for this malicious package. The package should be immediately removed from all affected systems. All secrets, keys, and credentials stored on the compromised machines must be rotated from a separate, trusted environment. Because the attacker may have persistent access beyond the package itself, consider a full system compromise response including forensic analysis and system rebuild if warranted. Monitor for any signs of further compromise.
Malicious code in data-parser-utils (npm)
Description
The npm package 'data-parser-utils' version 3.0.2 contains malicious code that executes shell commands to harvest shell history files such as ~/.bash_history and ~/.zsh_history. This behavior results in credential theft by exfiltrating sensitive information like tokens and connection strings from the affected system. The package's use of child_process execSync calls to run bash and zsh commands is inconsistent with its purported functionality, indicating malicious intent. Any system with this package installed should be considered fully compromised.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'data-parser-utils' npm package version 3.0.2 imports the Node.js 'child_process' module and uses execSync to run bash and zsh commands that read and exfiltrate shell history files. These files often contain sensitive credentials, tokens, and connection strings. The malicious code is reachable from the package's main entry point, confirming that the package is designed to steal operational credentials from the host machine. The presence of this code matches known malware fingerprints for shell-history harvesting. This malicious behavior compromises the confidentiality of secrets stored on the affected system.
Potential Impact
Systems with 'data-parser-utils' version 3.0.2 installed are fully compromised due to credential theft. Sensitive information such as credentials, tokens, and connection strings stored in shell history files may be exfiltrated by the malicious code. This can lead to unauthorized access to other systems and services. Because the package grants an attacker full control over the host, simply removing the package does not guarantee removal of all malicious artifacts or backdoors. Immediate secret rotation is required to mitigate ongoing risk.
Mitigation Recommendations
No official patch or fix is currently available for this malicious package. The package should be immediately removed from all affected systems. All secrets, keys, and credentials stored on the compromised machines must be rotated from a separate, trusted environment. Because the attacker may have persistent access beyond the package itself, consider a full system compromise response including forensic analysis and system rebuild if warranted. Monitor for any signs of further compromise.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-6490
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a3ef7ce27e9c79719002087
Added to database: 06/26/2026, 22:06:06 UTC
Last enriched: 07/30/2026, 09:21:17 UTC
Last updated: 07/30/2026, 09:21:17 UTC
Views: 45
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.