Malicious code in fetchcraft (npm)
The fetchcraft npm package versions 1.0.0 and 1.0.1 include a runtime dependency on a mutable tarball from a personal GitHub repository without integrity verification. This allows arbitrary code execution during installation, as the dependency can be changed at any time without modifying fetchcraft itself. The malicious code can fully compromise the host system, potentially exposing all stored secrets and keys. Removing the package may not fully remediate the compromise.
AI Analysis
Technical Summary
The fetchcraft npm package declares a runtime dependency on 'node-runtime-utils' fetched directly from the main branch of a personal GitHub repository via a tarball URL without commit SHA, tag, or integrity hash pinning. This mutable dependency can be altered at any time, enabling an attacker to execute arbitrary code during the npm install lifecycle scripts. The dependency is not used by fetchcraft's exported code, indicating no legitimate functional purpose and suggesting malicious intent. Systems with fetchcraft installed should be considered fully compromised.
Potential Impact
Any system with fetchcraft versions 1.0.0 or 1.0.1 installed is at risk of full compromise due to arbitrary code execution during package installation. Attackers may gain complete control over the affected system, potentially accessing and exfiltrating all stored secrets and keys. Because the malicious code executes during installation, the system's integrity and confidentiality are severely impacted. Removing the package does not guarantee removal of all malicious artifacts or backdoors.
Mitigation Recommendations
Immediate removal of the fetchcraft package versions 1.0.0 and 1.0.1 is recommended. All secrets and keys stored on the compromised system should be rotated from a separate, trusted machine. Due to the high risk of full system compromise, a full system forensic analysis and potential rebuild may be necessary. Patch status is not confirmed; no official fix or updated safe version is indicated. Users should avoid installing fetchcraft until a trusted, verified version is released.
Malicious code in fetchcraft (npm)
Description
The fetchcraft npm package versions 1.0.0 and 1.0.1 include a runtime dependency on a mutable tarball from a personal GitHub repository without integrity verification. This allows arbitrary code execution during installation, as the dependency can be changed at any time without modifying fetchcraft itself. The malicious code can fully compromise the host system, potentially exposing all stored secrets and keys. Removing the package may not fully remediate the compromise.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The fetchcraft npm package declares a runtime dependency on 'node-runtime-utils' fetched directly from the main branch of a personal GitHub repository via a tarball URL without commit SHA, tag, or integrity hash pinning. This mutable dependency can be altered at any time, enabling an attacker to execute arbitrary code during the npm install lifecycle scripts. The dependency is not used by fetchcraft's exported code, indicating no legitimate functional purpose and suggesting malicious intent. Systems with fetchcraft installed should be considered fully compromised.
Potential Impact
Any system with fetchcraft versions 1.0.0 or 1.0.1 installed is at risk of full compromise due to arbitrary code execution during package installation. Attackers may gain complete control over the affected system, potentially accessing and exfiltrating all stored secrets and keys. Because the malicious code executes during installation, the system's integrity and confidentiality are severely impacted. Removing the package does not guarantee removal of all malicious artifacts or backdoors.
Mitigation Recommendations
Immediate removal of the fetchcraft package versions 1.0.0 and 1.0.1 is recommended. All secrets and keys stored on the compromised system should be rotated from a separate, trusted machine. Due to the high risk of full system compromise, a full system forensic analysis and potential rebuild may be necessary. Patch status is not confirmed; no official fix or updated safe version is indicated. Users should avoid installing fetchcraft until a trusted, verified version is released.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10435
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-fg76-g9g4-9xpr"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a870a77acd9273b49b593b2
Added to database: 08/20/2026, 14:08:55 UTC
Last enriched: 08/20/2026, 14:36:28 UTC
Last updated: 08/20/2026, 22:26:36 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.