Malicious code in @dsft/ft-element (npm)
The npm package @dsft/ft-element version 2.5.9 contains malicious code that executes during installation. Its preinstall script sends a JSON beacon with the installing project's directory name to an attacker-controlled URL without user consent. This behavior leaks potentially sensitive project information and confirms a successful dependency-confusion attack. Although the author claims it is a harmless proof of concept, the unconditional data exfiltration constitutes a supply-chain attack. Systems with this package installed should be considered compromised, and secrets should be rotated immediately.
AI Analysis
Technical Summary
The @dsft/ft-element npm package version 2.5.9 includes a preinstall hook that runs index.js, which reads the environment variable INIT_CWD to determine the installing project's directory name. It then sends this information in a JSON payload to a hardcoded external URL (https://deepbounty.dd06-dev.fr/cb/e51c2215-3fa8-48f1-ad64-1cf792e0cccc). This action occurs silently during npm install without disclosure or consent, leaking potentially sensitive project identifiers. The package is published under the @dsft scope and is described by its author as a dependency-confusion proof of concept. Despite this, the behavior constitutes a supply-chain attack vector by confirming dependency-confusion takeover targets. The GHSA-malware advisory states that any system with this package installed should be considered fully compromised, recommending immediate secret rotation and package removal.
Potential Impact
The package leaks the installing project's directory name to an attacker-controlled endpoint during installation, which can reveal private project or repository names. This confirms successful dependency-confusion attacks and may enable further targeted attacks. The GHSA-malware advisory considers any system with this package installed as fully compromised, implying potential unauthorized control or data exposure. Secrets and keys stored on affected systems should be rotated immediately. Removal of the package alone may not eliminate all malicious software resulting from the compromise.
Mitigation Recommendations
No official patch or fix is currently available for this malicious package. Immediate removal of @dsft/ft-element version 2.5.9 from all systems is strongly recommended. All secrets and keys on affected systems should be rotated from a separate, uncompromised device. Monitor for any signs of further compromise. Avoid installing packages from untrusted or unknown scopes, and verify package authenticity before installation. Check vendor or repository advisories for updates or remediation guidance.
Malicious code in @dsft/ft-element (npm)
Description
The npm package @dsft/ft-element version 2.5.9 contains malicious code that executes during installation. Its preinstall script sends a JSON beacon with the installing project's directory name to an attacker-controlled URL without user consent. This behavior leaks potentially sensitive project information and confirms a successful dependency-confusion attack. Although the author claims it is a harmless proof of concept, the unconditional data exfiltration constitutes a supply-chain attack. Systems with this package installed should be considered compromised, and secrets should be rotated immediately.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The @dsft/ft-element npm package version 2.5.9 includes a preinstall hook that runs index.js, which reads the environment variable INIT_CWD to determine the installing project's directory name. It then sends this information in a JSON payload to a hardcoded external URL (https://deepbounty.dd06-dev.fr/cb/e51c2215-3fa8-48f1-ad64-1cf792e0cccc). This action occurs silently during npm install without disclosure or consent, leaking potentially sensitive project identifiers. The package is published under the @dsft scope and is described by its author as a dependency-confusion proof of concept. Despite this, the behavior constitutes a supply-chain attack vector by confirming dependency-confusion takeover targets. The GHSA-malware advisory states that any system with this package installed should be considered fully compromised, recommending immediate secret rotation and package removal.
Potential Impact
The package leaks the installing project's directory name to an attacker-controlled endpoint during installation, which can reveal private project or repository names. This confirms successful dependency-confusion attacks and may enable further targeted attacks. The GHSA-malware advisory considers any system with this package installed as fully compromised, implying potential unauthorized control or data exposure. Secrets and keys stored on affected systems should be rotated immediately. Removal of the package alone may not eliminate all malicious software resulting from the compromise.
Mitigation Recommendations
No official patch or fix is currently available for this malicious package. Immediate removal of @dsft/ft-element version 2.5.9 from all systems is strongly recommended. All secrets and keys on affected systems should be rotated from a separate, uncompromised device. Monitor for any signs of further compromise. Avoid installing packages from untrusted or unknown scopes, and verify package authenticity before installation. Check vendor or repository advisories for updates or remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-5889
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-5g88-35hm-8xr7"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a577eee68715ace43b414b7
Added to database: 07/15/2026, 12:37:02 UTC
Last enriched: 07/15/2026, 12:55:45 UTC
Last updated: 07/23/2026, 12:02:41 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.