Malicious code in flydev (npm)
Description
The flydev npm package version 0.0.1 is a malicious package that contains a destructive payload. It hides its harmful code in a deeply nested directory structure and exports a function that, when invoked, executes multiple destructive actions on Windows hosts. These actions include forced system reboot, recursive deletion of files on the C: drive, termination of critical system processes, memory exhaustion, and spawning a self-replicating fork bomb that creates numerous detached command and PowerShell processes. The package has no legitimate functionality and is designed to cause severe damage to the host system.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The flydev package (npm ecosystem) version 0.0.1 is a malicious package masquerading as a utility. Its exported function triggers 26 sibling modules that perform destructive operations on Windows systems: forced reboot via 'shutdown /r /f /t 0', recursive deletion of files on the C: drive using 'del /F /S /Q C:\*.*' and fs.unlinkSync, termination of critical OS processes (explorer, dwm, csrss) via wmic commands, memory exhaustion through unbounded array allocations, and a self-replicating fork bomb implemented by spawning hundreds of detached cmd and PowerShell infinite-loop processes. The package's structure and naming indicate deliberate deception with no legitimate functionality. Invocation results in filesystem destruction, critical process termination, and an unrecoverable reboot and process explosion loop.
Potential Impact
If executed, this package will cause immediate and severe damage to the affected Windows host by deleting files recursively on the C: drive, terminating essential system processes, exhausting system memory, and causing continuous system reboots and process explosions. This results in system instability, data loss, and denial of service. The damage is destructive and unrecoverable without restoration from backups or system reinstallation.
Mitigation Recommendations
No official patch or remediation is available for this malicious package. The best mitigation is to avoid installing or executing the flydev package version 0.0.1. Security teams should block this package from their environments and remove it if already present. Since this is a malicious package with no legitimate functionality, do not invoke its exported functions. Employ standard supply chain security practices such as verifying package integrity and using trusted sources.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-14243
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a85b4c2acd9273b492524bb
Added to database: 08/19/2026, 13:50:58 UTC
Last enriched: 08/19/2026, 14:29:10 UTC
Last updated: 10/02/2026, 13:52:10 UTC
Views: 25
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.