Malicious code in fkext-browser-min (npm)
The npm package fkext-browser-min version 1.0.14 contains malicious code executed during installation. It runs a script that collects the machine's public IP, hostname, and GitHub Actions/CI environment variables, then sends this data to an attacker-controlled webhook URL. It also performs a DNS lookup to an attacker-controlled domain to exfiltrate data via an out-of-band channel. The package has no legitimate functionality and is designed solely for reconnaissance and data exfiltration during installation.
AI Analysis
Technical Summary
The fkext-browser-min npm package version 1.0.14 executes a preinstall lifecycle hook script named vishu.js upon installation. This script collects sensitive environment information including the public IP address (via api.ipify.org), the system hostname, and GitHub Actions/CI environment variables (GITHUB_*). It transmits this information to a hardcoded webhook.site URL over HTTPS. Additionally, it performs a DNS lookup to a subdomain formatted as ping-<hostname>.<collaborator>.oastify.com, providing an out-of-band exfiltration channel that can bypass HTTP egress filters. The package does not provide any legitimate functionality and is identified as a malicious package used for reconnaissance and beaconing in installer or CI environments.
Potential Impact
This malicious package can leak sensitive environment information from the host machine and CI environments to an attacker-controlled server during installation. This exposure can aid attackers in profiling the target environment for further attacks or exploitation. The out-of-band DNS exfiltration channel can bypass some network egress restrictions, increasing the risk of data leakage. There is no indication of direct code execution beyond the preinstall script or further payload delivery.
Mitigation Recommendations
No official patch or remediation is documented for this package. Users should avoid installing fkext-browser-min version 1.0.14 and remove it if present. Review and restrict package sources and dependencies to trusted repositories to prevent supply chain attacks. Monitor CI environments for unauthorized package installations and consider implementing policies to block or audit preinstall scripts. Since no fix is stated, patch status is not yet confirmed — check vendor or repository advisories for updates.
Malicious code in fkext-browser-min (npm)
Description
The npm package fkext-browser-min version 1.0.14 contains malicious code executed during installation. It runs a script that collects the machine's public IP, hostname, and GitHub Actions/CI environment variables, then sends this data to an attacker-controlled webhook URL. It also performs a DNS lookup to an attacker-controlled domain to exfiltrate data via an out-of-band channel. The package has no legitimate functionality and is designed solely for reconnaissance and data exfiltration during installation.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The fkext-browser-min npm package version 1.0.14 executes a preinstall lifecycle hook script named vishu.js upon installation. This script collects sensitive environment information including the public IP address (via api.ipify.org), the system hostname, and GitHub Actions/CI environment variables (GITHUB_*). It transmits this information to a hardcoded webhook.site URL over HTTPS. Additionally, it performs a DNS lookup to a subdomain formatted as ping-<hostname>.<collaborator>.oastify.com, providing an out-of-band exfiltration channel that can bypass HTTP egress filters. The package does not provide any legitimate functionality and is identified as a malicious package used for reconnaissance and beaconing in installer or CI environments.
Potential Impact
This malicious package can leak sensitive environment information from the host machine and CI environments to an attacker-controlled server during installation. This exposure can aid attackers in profiling the target environment for further attacks or exploitation. The out-of-band DNS exfiltration channel can bypass some network egress restrictions, increasing the risk of data leakage. There is no indication of direct code execution beyond the preinstall script or further payload delivery.
Mitigation Recommendations
No official patch or remediation is documented for this package. Users should avoid installing fkext-browser-min version 1.0.14 and remove it if present. Review and restrict package sources and dependencies to trusted repositories to prevent supply chain attacks. Monitor CI environments for unauthorized package installations and consider implementing policies to block or audit preinstall scripts. Since no fix is stated, patch status is not yet confirmed — check vendor or repository advisories for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10183
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a520ea768715ace438f4467
Added to database: 07/11/2026, 09:36:39 UTC
Last enriched: 09/12/2026, 19:01:46 UTC
Last updated: 09/12/2026, 19:01:46 UTC
Views: 45
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.