Skip to main content

Malicious code in flydev (npm)

0
Critical
Published: 08/19/2026 (08/19/2026, 04:08:23 UTC)
Source: GCVE Database
Product: flydev

Description

The flydev npm package version 0.0.1 is a malicious package that contains a destructive payload. It hides its harmful code in a deeply nested directory structure and exports a function that, when invoked, executes multiple destructive actions on Windows hosts. These actions include forced system reboot, recursive deletion of files on the C: drive, termination of critical system processes, memory exhaustion, and spawning a self-replicating fork bomb that creates numerous detached command and PowerShell processes. The package has no legitimate functionality and is designed to cause severe damage to the host system.

Affected software

npmghsa
flydev
Affected versions
=0.0.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/19/2026, 14:29:10 UTC

Technical Analysis

The flydev package (npm ecosystem) version 0.0.1 is a malicious package masquerading as a utility. Its exported function triggers 26 sibling modules that perform destructive operations on Windows systems: forced reboot via 'shutdown /r /f /t 0', recursive deletion of files on the C: drive using 'del /F /S /Q C:\*.*' and fs.unlinkSync, termination of critical OS processes (explorer, dwm, csrss) via wmic commands, memory exhaustion through unbounded array allocations, and a self-replicating fork bomb implemented by spawning hundreds of detached cmd and PowerShell infinite-loop processes. The package's structure and naming indicate deliberate deception with no legitimate functionality. Invocation results in filesystem destruction, critical process termination, and an unrecoverable reboot and process explosion loop.

Potential Impact

If executed, this package will cause immediate and severe damage to the affected Windows host by deleting files recursively on the C: drive, terminating essential system processes, exhausting system memory, and causing continuous system reboots and process explosions. This results in system instability, data loss, and denial of service. The damage is destructive and unrecoverable without restoration from backups or system reinstallation.

Mitigation Recommendations

No official patch or remediation is available for this malicious package. The best mitigation is to avoid installing or executing the flydev package version 0.0.1. Security teams should block this package from their environments and remove it if already present. Since this is a malicious package with no legitimate functionality, do not invoke its exported functions. Employ standard supply chain security practices such as verifying package integrity and using trusted sources.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-14243
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6a85b4c2acd9273b492524bb

Added to database: 08/19/2026, 13:50:58 UTC

Last enriched: 08/19/2026, 14:29:10 UTC

Last updated: 10/02/2026, 13:52:10 UTC

Views: 25

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses