Malicious code in @doaction/auth (npm)
The @doaction/auth npm package contains undisclosed telemetry that transmits environment data to Datadog at install time without user consent. This behavior breaks air-gapped installation policies and does not provide an opt-out mechanism. The package's preinstall script loads code from a sibling package (@doaction/shared) which performs the data transmission. Although the destination is a commercial observability service rather than attacker infrastructure, the telemetry is consent-violating. A related advisory states that any system with this package installed should be considered fully compromised and recommends immediate secret/key rotation and package removal. No official patch or fix is currently documented.
AI Analysis
Technical Summary
The @doaction/auth npm package declares a preinstall script that requires a sibling package (@doaction/shared) which transmits environment data to Datadog's API at install time. The telemetry includes authentication-related environment variables but requires a caller-supplied API key for explicit reporting, making the install-time transmission undisclosed and non-optional. The package's lifecycle scripts are confusingly named, reducing review clarity. The telemetry targets a commercial SaaS rather than attacker-controlled infrastructure, indicating the issue is undisclosed telemetry rather than direct credential exfiltration. However, a related advisory from ghsa-malware states that any computer with this package installed should be considered fully compromised, recommending secret rotation and removal. No patch or remediation is currently available.
Potential Impact
Installation of this package results in environment data being transmitted to an external commercial telemetry service without user consent, violating privacy and security policies, especially in air-gapped or sensitive environments. According to a related advisory, the presence of this package implies full system compromise, necessitating secret and key rotation. The package may enable unauthorized data exposure and potential further compromise due to undisclosed telemetry behavior.
Mitigation Recommendations
No official patch or fix is currently available for this package. Users should immediately remove the @doaction/auth package if installed. All secrets and keys on affected systems should be rotated from a separate, trusted environment. Due to the potential full compromise indicated by the advisory, a thorough system investigation and remediation is recommended. Monitor vendor advisories for updates or official remediation guidance.
Malicious code in @doaction/auth (npm)
Description
The @doaction/auth npm package contains undisclosed telemetry that transmits environment data to Datadog at install time without user consent. This behavior breaks air-gapped installation policies and does not provide an opt-out mechanism. The package's preinstall script loads code from a sibling package (@doaction/shared) which performs the data transmission. Although the destination is a commercial observability service rather than attacker infrastructure, the telemetry is consent-violating. A related advisory states that any system with this package installed should be considered fully compromised and recommends immediate secret/key rotation and package removal. No official patch or fix is currently documented.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The @doaction/auth npm package declares a preinstall script that requires a sibling package (@doaction/shared) which transmits environment data to Datadog's API at install time. The telemetry includes authentication-related environment variables but requires a caller-supplied API key for explicit reporting, making the install-time transmission undisclosed and non-optional. The package's lifecycle scripts are confusingly named, reducing review clarity. The telemetry targets a commercial SaaS rather than attacker-controlled infrastructure, indicating the issue is undisclosed telemetry rather than direct credential exfiltration. However, a related advisory from ghsa-malware states that any computer with this package installed should be considered fully compromised, recommending secret rotation and removal. No patch or remediation is currently available.
Potential Impact
Installation of this package results in environment data being transmitted to an external commercial telemetry service without user consent, violating privacy and security policies, especially in air-gapped or sensitive environments. According to a related advisory, the presence of this package implies full system compromise, necessitating secret and key rotation. The package may enable unauthorized data exposure and potential further compromise due to undisclosed telemetry behavior.
Mitigation Recommendations
No official patch or fix is currently available for this package. Users should immediately remove the @doaction/auth package if installed. All secrets and keys on affected systems should be rotated from a separate, trusted environment. Due to the potential full compromise indicated by the advisory, a thorough system investigation and remediation is recommended. Monitor vendor advisories for updates or official remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-5369
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-5cwj-c46v-mpmf"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a4f6c4568715ace431591f6
Added to database: 07/09/2026, 09:39:17 UTC
Last enriched: 07/09/2026, 09:55:49 UTC
Last updated: 07/28/2026, 17:29:50 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.