Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in @doaction/auth (npm)

0
Critical
Published: 06/09/2026 (06/09/2026, 14:17:41 UTC)
Source: GCVE Database
Product: @doaction/auth

Description

The @doaction/auth npm package contains undisclosed telemetry that transmits environment data to Datadog at install time without user consent. This behavior breaks air-gapped installation policies and does not provide an opt-out mechanism. The package's preinstall script loads code from a sibling package (@doaction/shared) which performs the data transmission. Although the destination is a commercial observability service rather than attacker infrastructure, the telemetry is consent-violating. A related advisory states that any system with this package installed should be considered fully compromised and recommends immediate secret/key rotation and package removal. No official patch or fix is currently documented.

Affected software

npmghsa
@doaction/auth
Affected versions
=99.99.99=9.9.9

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/09/2026, 09:55:49 UTC

Technical Analysis

The @doaction/auth npm package declares a preinstall script that requires a sibling package (@doaction/shared) which transmits environment data to Datadog's API at install time. The telemetry includes authentication-related environment variables but requires a caller-supplied API key for explicit reporting, making the install-time transmission undisclosed and non-optional. The package's lifecycle scripts are confusingly named, reducing review clarity. The telemetry targets a commercial SaaS rather than attacker-controlled infrastructure, indicating the issue is undisclosed telemetry rather than direct credential exfiltration. However, a related advisory from ghsa-malware states that any computer with this package installed should be considered fully compromised, recommending secret rotation and removal. No patch or remediation is currently available.

Potential Impact

Installation of this package results in environment data being transmitted to an external commercial telemetry service without user consent, violating privacy and security policies, especially in air-gapped or sensitive environments. According to a related advisory, the presence of this package implies full system compromise, necessitating secret and key rotation. The package may enable unauthorized data exposure and potential further compromise due to undisclosed telemetry behavior.

Mitigation Recommendations

No official patch or fix is currently available for this package. Users should immediately remove the @doaction/auth package if installed. All secrets and keys on affected systems should be rotated from a separate, trusted environment. Due to the potential full compromise indicated by the advisory, a thorough system investigation and remediation is recommended. Monitor vendor advisories for updates or official remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-5369
Osv Schema Version
1.7.4
Aliases
["GHSA-5cwj-c46v-mpmf"]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a4f6c4568715ace431591f6

Added to database: 07/09/2026, 09:39:17 UTC

Last enriched: 07/09/2026, 09:55:49 UTC

Last updated: 07/28/2026, 17:29:50 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses