Malicious code in fluterjs (npm)
The npm package fluterjs version 1.0.0 contains malicious code that starts an Express server exposing a POST endpoint /ejecutar. This endpoint accepts a JSON field 'comando' and executes it directly on the host system without any authentication, origin checks, or command restrictions. This behavior effectively creates a remote shell backdoor, allowing any network-accessible attacker to execute arbitrary commands as the user running the package. The package masquerades as a terminal helper but is intentionally designed to provide unauthorized remote code execution.
AI Analysis
Technical Summary
fluterjs version 1.0.0 includes a backdoor implemented as an Express server listening on 0.0.0.0:10459 with a POST /ejecutar endpoint. The endpoint reads the 'comando' field from incoming JSON requests and passes it directly to child_process.exec without any authentication or validation. This design allows any network-reachable entity to execute arbitrary shell commands on the host with the privileges of the user who started the process. This is a deliberate malicious feature disguised as a legitimate terminal helper package.
Potential Impact
An attacker with network access to the host running fluterjs 1.0.0 can execute arbitrary shell commands remotely with the same privileges as the user running the package. This can lead to full system compromise, data theft, or further lateral movement. There are no built-in protections such as authentication or command filtering, making exploitation trivial if the host is exposed to untrusted networks.
Mitigation Recommendations
No official patch or remediation is currently available for fluterjs 1.0.0. Users should immediately uninstall this package and avoid running it in any environment. Network exposure of hosts running this package should be restricted or blocked. Monitor for any usage of this package and remove it from all systems. Since this is a malicious package by design, do not attempt to use or trust it.
Malicious code in fluterjs (npm)
Description
The npm package fluterjs version 1.0.0 contains malicious code that starts an Express server exposing a POST endpoint /ejecutar. This endpoint accepts a JSON field 'comando' and executes it directly on the host system without any authentication, origin checks, or command restrictions. This behavior effectively creates a remote shell backdoor, allowing any network-accessible attacker to execute arbitrary commands as the user running the package. The package masquerades as a terminal helper but is intentionally designed to provide unauthorized remote code execution.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
fluterjs version 1.0.0 includes a backdoor implemented as an Express server listening on 0.0.0.0:10459 with a POST /ejecutar endpoint. The endpoint reads the 'comando' field from incoming JSON requests and passes it directly to child_process.exec without any authentication or validation. This design allows any network-reachable entity to execute arbitrary shell commands on the host with the privileges of the user who started the process. This is a deliberate malicious feature disguised as a legitimate terminal helper package.
Potential Impact
An attacker with network access to the host running fluterjs 1.0.0 can execute arbitrary shell commands remotely with the same privileges as the user running the package. This can lead to full system compromise, data theft, or further lateral movement. There are no built-in protections such as authentication or command filtering, making exploitation trivial if the host is exposed to untrusted networks.
Mitigation Recommendations
No official patch or remediation is currently available for fluterjs 1.0.0. Users should immediately uninstall this package and avoid running it in any environment. Network exposure of hosts running this package should be restricted or blocked. Monitor for any usage of this package and remove it from all systems. Since this is a malicious package by design, do not attempt to use or trust it.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10532
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a55ff6468715ace432f1b8b
Added to database: 07/14/2026, 09:20:36 UTC
Last enriched: 07/14/2026, 09:32:40 UTC
Last updated: 07/22/2026, 12:07:27 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.