Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in @ferudionz/webautomation (npm)

0
High
Published: 08/14/2026 (08/14/2026, 19:03:57 UTC)
Source: GCVE Database
Product: @ferudionz/webautomation

Description

The npm package @ferudionz/webautomation version 1.0.0 contains malicious code that exfiltrates caller-supplied data to a hidden remote server. The package exposes a single function, connet(x), which sends its argument to an obfuscated and runtime-reconstructed URL, hiding the destination from static analysis. The package lacks legitimate documentation, author metadata, and presents itself misleadingly as a generic logger tool. This behavior indicates intentional data theft rather than legitimate functionality.

Affected software

npmghsa
@ferudionz/webautomation
Affected versions
=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/15/2026, 05:42:12 UTC

Technical Analysis

The @ferudionz/webautomation npm package (version 1.0.0) includes a function connet(x) that posts the argument it receives to a hardcoded remote URL. The code is heavily obfuscated using RC4 string arrays and anti-debugging techniques, with the destination URL reconstructed at runtime from multiple decoded fragments to evade detection. The package does not document any legitimate service endpoint and has empty author metadata. The argument passed to connet() is likely a wallet or account identifier, which is silently exfiltrated to an undisclosed, author-controlled server. The combination of obfuscation, anti-debugging, and misleading presentation strongly suggests malicious intent.

Potential Impact

Sensitive data passed to the connet() function, such as wallet or account identifiers, is exfiltrated to a remote attacker-controlled server without user consent or knowledge. This can lead to privacy violations, credential theft, or further targeted attacks depending on the nature of the exfiltrated data. There is no indication of direct code execution or system compromise beyond data leakage.

Mitigation Recommendations

No official patch or remediation is currently available. Users should immediately remove the @ferudionz/webautomation package version 1.0.0 from their projects and avoid using it. Consider auditing dependencies for similar malicious packages and monitor for suspicious network activity related to unknown remote endpoints. Check vendor advisories or trusted security sources for updates on remediation or replacement packages.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-14045
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a7ff5fabf8831d5398804aa

Added to database: 08/15/2026, 05:15:38 UTC

Last enriched: 08/15/2026, 05:42:12 UTC

Last updated: 08/15/2026, 09:50:12 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses