Malicious code in filewisee (npm)
The npm package 'filewisee' versions 0.1.0 and 0.1.1 contains malicious code disguised as a date-formatting utility. It exports a function 'formatd' that, when called, downloads an unsigned binary from an anonymous external host, saves it in a hidden directory under the user's home, sets executable permissions, and executes it hidden from the user. This behavior is unrelated to the package's stated functionality and poses a security risk.
AI Analysis
Technical Summary
The 'filewisee' npm package masquerades as a date-formatting library but includes a malicious function 'formatd' that downloads and executes an opaque binary from an anonymous file host (pixeldrain.com) without any integrity verification. The binary is stored in a hidden directory (~/.drc/dr) with executable permissions and launched with hidden process settings, increasing the risk of unnoticed malicious activity. The package versions 0.1.0 and 0.1.1 are affected. There is no CVSS score or known exploits in the wild reported.
Potential Impact
The malicious code can lead to arbitrary code execution on the user's system by downloading and running an unverified binary from an untrusted source. This can compromise system integrity, confidentiality, and availability depending on the payload of the downloaded binary. The hidden execution and storage increase stealth, making detection and response more difficult.
Mitigation Recommendations
No official patch or remediation is currently available. Users should avoid installing or using the 'filewisee' package versions 0.1.0 and 0.1.1. If already installed, remove the package and delete the hidden directory '~/.drc' to eliminate the downloaded binary. Monitor for any suspicious activity related to this package. Check for vendor advisories or updates for any future fixes.
Malicious code in filewisee (npm)
Description
The npm package 'filewisee' versions 0.1.0 and 0.1.1 contains malicious code disguised as a date-formatting utility. It exports a function 'formatd' that, when called, downloads an unsigned binary from an anonymous external host, saves it in a hidden directory under the user's home, sets executable permissions, and executes it hidden from the user. This behavior is unrelated to the package's stated functionality and poses a security risk.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'filewisee' npm package masquerades as a date-formatting library but includes a malicious function 'formatd' that downloads and executes an opaque binary from an anonymous file host (pixeldrain.com) without any integrity verification. The binary is stored in a hidden directory (~/.drc/dr) with executable permissions and launched with hidden process settings, increasing the risk of unnoticed malicious activity. The package versions 0.1.0 and 0.1.1 are affected. There is no CVSS score or known exploits in the wild reported.
Potential Impact
The malicious code can lead to arbitrary code execution on the user's system by downloading and running an unverified binary from an untrusted source. This can compromise system integrity, confidentiality, and availability depending on the payload of the downloaded binary. The hidden execution and storage increase stealth, making detection and response more difficult.
Mitigation Recommendations
No official patch or remediation is currently available. Users should avoid installing or using the 'filewisee' package versions 0.1.0 and 0.1.1. If already installed, remove the package and delete the hidden directory '~/.drc' to eliminate the downloaded binary. Monitor for any suspicious activity related to this package. Check for vendor advisories or updates for any future fixes.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10501
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a55ff9068715ace432f4b21
Added to database: 07/14/2026, 09:21:20 UTC
Last enriched: 07/14/2026, 09:48:38 UTC
Last updated: 07/29/2026, 03:54:28 UTC
Views: 26
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.