Skip to main content

Malicious code in fkext-browser-min (npm)

0
High
Published: 07/10/2026 (07/10/2026, 22:43:30 UTC)
Source: GCVE Database
Product: fkext-browser-min

Description

The npm package fkext-browser-min version 1.0.14 contains malicious code executed during installation. It runs a script that collects the machine's public IP, hostname, and GitHub Actions/CI environment variables, then sends this data to an attacker-controlled webhook URL. It also performs a DNS lookup to an attacker-controlled domain to exfiltrate data via an out-of-band channel. The package has no legitimate functionality and is designed solely for reconnaissance and data exfiltration during installation.

Affected software

npmghsa
fkext-browser-min
Affected versions
=1.0.14

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/12/2026, 19:01:46 UTC

Technical Analysis

The fkext-browser-min npm package version 1.0.14 executes a preinstall lifecycle hook script named vishu.js upon installation. This script collects sensitive environment information including the public IP address (via api.ipify.org), the system hostname, and GitHub Actions/CI environment variables (GITHUB_*). It transmits this information to a hardcoded webhook.site URL over HTTPS. Additionally, it performs a DNS lookup to a subdomain formatted as ping-<hostname>.<collaborator>.oastify.com, providing an out-of-band exfiltration channel that can bypass HTTP egress filters. The package does not provide any legitimate functionality and is identified as a malicious package used for reconnaissance and beaconing in installer or CI environments.

Potential Impact

This malicious package can leak sensitive environment information from the host machine and CI environments to an attacker-controlled server during installation. This exposure can aid attackers in profiling the target environment for further attacks or exploitation. The out-of-band DNS exfiltration channel can bypass some network egress restrictions, increasing the risk of data leakage. There is no indication of direct code execution beyond the preinstall script or further payload delivery.

Mitigation Recommendations

No official patch or remediation is documented for this package. Users should avoid installing fkext-browser-min version 1.0.14 and remove it if present. Review and restrict package sources and dependencies to trusted repositories to prevent supply chain attacks. Monitor CI environments for unauthorized package installations and consider implementing policies to block or audit preinstall scripts. Since no fix is stated, patch status is not yet confirmed — check vendor or repository advisories for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-10183
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6a520ea768715ace438f4467

Added to database: 07/11/2026, 09:36:39 UTC

Last enriched: 09/12/2026, 19:01:46 UTC

Last updated: 09/12/2026, 19:01:46 UTC

Views: 45

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses