Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in dateuuidv2 (npm)

0
Critical
Published: 08/05/2026 (08/05/2026, 09:16:51 UTC)
Source: GCVE Database
Product: dateuuidv2

Description

The npm package dateuuidv2, advertised as a UUID v7 generator, contains malicious code that executes at require time. It reads a PORT= value from a README.md file to reconstruct an AES-256-GCM key and decrypt a hardcoded ciphertext to obtain a command-and-control (C2) URL. The package then sends system information to this URL and executes the response as a script on Windows systems. This behavior is unrelated to the advertised UUID functionality and includes multiple evasion techniques.

Affected software

npmghsa
dateuuidv2
Affected versions
=1.0.1=1.0.0=1.0.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/05/2026, 17:05:18 UTC

Technical Analysis

The dateuuidv2 npm package versions 1.0.0, 1.0.1, and 1.0.2 include malicious code in their main entry point (lib/bootstrap.js). Upon requiring the package, it calls extractDateISO(), which reads a PORT= value from README.md in the current working directory. This value is used to reconstruct an AES-256-GCM key and IV to decrypt a hardcoded ciphertext containing a C2 URL. The package then posts the installer's OS platform and release string to this URL. On Windows, it writes the response to a temporary .vbs file and executes it via child_process.exec, then deletes the file. The package uses multiple evasion layers such as encrypted C2 URLs, key material sourced from an operator-seeded file, and obfuscated script file extension construction. The advertised UUID generation functionality is unrelated to this malicious network and code execution behavior.

Potential Impact

The malicious code enables remote code execution on the host system by downloading and running arbitrary scripts from a command-and-control server. This compromises system integrity and confidentiality. The package exfiltrates system information (OS platform and release) to the attacker-controlled server. This behavior can lead to further compromise or persistence on affected systems.

Mitigation Recommendations

No official patch or remediation is currently documented. Users should immediately stop using the dateuuidv2 package versions 1.0.0, 1.0.1, and 1.0.2. Remove these versions from projects and replace them with trusted alternatives. Verify that no unauthorized scripts have been executed on affected systems. Monitor for suspicious network activity related to unknown C2 URLs. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-12176
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a735741bf8831d5391576ab

Added to database: 08/05/2026, 15:31:13 UTC

Last enriched: 08/05/2026, 17:05:18 UTC

Last updated: 08/05/2026, 17:05:18 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses