Malicious code in dateuuidv2 (npm)
The npm package dateuuidv2, advertised as a UUID v7 generator, contains malicious code that executes at require time. It reads a PORT= value from a README.md file to reconstruct an AES-256-GCM key and decrypt a hardcoded ciphertext to obtain a command-and-control (C2) URL. The package then sends system information to this URL and executes the response as a script on Windows systems. This behavior is unrelated to the advertised UUID functionality and includes multiple evasion techniques.
AI Analysis
Technical Summary
The dateuuidv2 npm package versions 1.0.0, 1.0.1, and 1.0.2 include malicious code in their main entry point (lib/bootstrap.js). Upon requiring the package, it calls extractDateISO(), which reads a PORT= value from README.md in the current working directory. This value is used to reconstruct an AES-256-GCM key and IV to decrypt a hardcoded ciphertext containing a C2 URL. The package then posts the installer's OS platform and release string to this URL. On Windows, it writes the response to a temporary .vbs file and executes it via child_process.exec, then deletes the file. The package uses multiple evasion layers such as encrypted C2 URLs, key material sourced from an operator-seeded file, and obfuscated script file extension construction. The advertised UUID generation functionality is unrelated to this malicious network and code execution behavior.
Potential Impact
The malicious code enables remote code execution on the host system by downloading and running arbitrary scripts from a command-and-control server. This compromises system integrity and confidentiality. The package exfiltrates system information (OS platform and release) to the attacker-controlled server. This behavior can lead to further compromise or persistence on affected systems.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately stop using the dateuuidv2 package versions 1.0.0, 1.0.1, and 1.0.2. Remove these versions from projects and replace them with trusted alternatives. Verify that no unauthorized scripts have been executed on affected systems. Monitor for suspicious network activity related to unknown C2 URLs. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for updates.
Malicious code in dateuuidv2 (npm)
Description
The npm package dateuuidv2, advertised as a UUID v7 generator, contains malicious code that executes at require time. It reads a PORT= value from a README.md file to reconstruct an AES-256-GCM key and decrypt a hardcoded ciphertext to obtain a command-and-control (C2) URL. The package then sends system information to this URL and executes the response as a script on Windows systems. This behavior is unrelated to the advertised UUID functionality and includes multiple evasion techniques.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The dateuuidv2 npm package versions 1.0.0, 1.0.1, and 1.0.2 include malicious code in their main entry point (lib/bootstrap.js). Upon requiring the package, it calls extractDateISO(), which reads a PORT= value from README.md in the current working directory. This value is used to reconstruct an AES-256-GCM key and IV to decrypt a hardcoded ciphertext containing a C2 URL. The package then posts the installer's OS platform and release string to this URL. On Windows, it writes the response to a temporary .vbs file and executes it via child_process.exec, then deletes the file. The package uses multiple evasion layers such as encrypted C2 URLs, key material sourced from an operator-seeded file, and obfuscated script file extension construction. The advertised UUID generation functionality is unrelated to this malicious network and code execution behavior.
Potential Impact
The malicious code enables remote code execution on the host system by downloading and running arbitrary scripts from a command-and-control server. This compromises system integrity and confidentiality. The package exfiltrates system information (OS platform and release) to the attacker-controlled server. This behavior can lead to further compromise or persistence on affected systems.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately stop using the dateuuidv2 package versions 1.0.0, 1.0.1, and 1.0.2. Remove these versions from projects and replace them with trusted alternatives. Verify that no unauthorized scripts have been executed on affected systems. Monitor for suspicious network activity related to unknown C2 URLs. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12176
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a735741bf8831d5391576ab
Added to database: 08/05/2026, 15:31:13 UTC
Last enriched: 08/05/2026, 17:05:18 UTC
Last updated: 08/05/2026, 17:05:18 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.