Malicious code in fetch-page-assets (npm)
Description
The npm package fetch-page-assets contains malicious code embedded in its babel.config.cjs and a disguised JavaScript file masquerading as a font. This code dynamically fetches and executes attacker-controlled payloads resolved via Ethereum blockchain transactions, enabling resilient command-and-control (C2) on compromised machines. Any system running this package with a Babel-based workflow is at risk of remote code execution and full compromise.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The fetch-page-assets npm package versions 1.2.9, 1.2.13, and 1.2.14 include heavily obfuscated malicious code within babel.config.cjs and a file disguised as a font (public/fonts/fa-solid-400.woff2). The malicious code queries multiple Ethereum RPC endpoints for transactions from a specific on-chain address to dynamically retrieve XOR-encrypted secondary payloads from attacker-controlled C2 servers. These payloads are decrypted with hardcoded keys and executed locally via eval and detached Node.js processes. The code uses Unicode-escaped requires to evade static detection. This mechanism provides the attacker with resilient, takedown-resistant remote code execution capabilities on any machine that installs and runs this package in a Babel-based environment such as jest, build, or transpile workflows.
Potential Impact
Systems that install and run fetch-page-assets versions 1.2.9, 1.2.13, or 1.2.14 with Babel-based workflows are subject to remote code execution by attacker-controlled payloads. This results in full compromise of the affected computer, including potential unauthorized access to secrets and keys stored on the system. The attacker gains persistent, resilient command-and-control capabilities that are dynamically resolved via the Ethereum blockchain, making takedown and remediation difficult.
Mitigation Recommendations
No official patch or remediation is currently documented. Immediate removal of the fetch-page-assets package versions 1.2.9, 1.2.13, and 1.2.14 is strongly recommended. All secrets and keys on affected systems should be rotated from a separate, uncompromised device. Due to the nature of the compromise, assume full system compromise and consider rebuilding the affected machines. Monitor for any suspicious activity related to this package and avoid using it until a verified clean version is available.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-6358
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-vxq2-vhm7-7mhq"]
- Ecosystems
- ["npm"]
Threat ID: 6a8d9ae8acd9273b493e17b5
Added to database: 08/25/2026, 13:38:48 UTC
Last enriched: 09/10/2026, 18:48:00 UTC
Last updated: 10/02/2026, 14:22:10 UTC
Views: 23
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.