Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in gaarf-node-bq (npm)

0
Medium
Published: 08/19/2026 (08/19/2026, 03:48:45 UTC)
Source: GCVE Database
Product: gaarf-node-bq

Description

The npm package 'gaarf-node-bq' version 1.0.0 is a malicious typosquatting package targeting the internal 'gaarf' package used by Google Ads API report fetcher. It contains a postinstall script that collects host metadata such as hostname, platform, architecture, Node.js version, package name, and npm lifecycle event, then sends this data without user consent to a hardcoded external endpoint. The package itself provides no legitimate functionality and acts as a canary for dependency confusion attacks.

Affected software

npmghsa
gaarf-node-bq
Affected versions
=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/19/2026, 14:30:46 UTC

Technical Analysis

The 'gaarf-node-bq' npm package (version 1.0.0) is a malicious package designed for dependency confusion or typosquatting attacks. It mimics the internal 'gaarf' package to trick users or automated systems into installing it from the public npm registry instead of the intended private package. Upon installation, its postinstall lifecycle script collects host identifiers including os.hostname(), platform, architecture, Node.js version, package name, and npm lifecycle event, then exfiltrates this information as JSON to a hardcoded external URL (https://yu7pug2j.instances.poc.jchunt.top/gaarf-node-bq). The package contains no real functionality beyond this data collection and exfiltration, making it a privacy and security risk for any environment where it is mistakenly installed.

Potential Impact

Hosts that inadvertently install 'gaarf-node-bq' version 1.0.0 will have system metadata and environment details sent without consent to an external attacker-controlled endpoint. This could lead to information leakage about the host environment, which may be used for further targeted attacks or reconnaissance. There is no indication of additional payloads or direct system compromise beyond this data exfiltration.

Mitigation Recommendations

No official patch or remediation is available since this is a malicious package published to the public npm registry. The primary mitigation is to ensure that package resolution correctly points to the intended private 'gaarf' package and to audit dependencies for typosquatting or dependency confusion risks. Avoid installing packages with names similar to internal private packages from public registries. Monitor package sources and use package allowlists or scoped registries to prevent accidental installation of malicious typosquat packages.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-14239
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a85b4c2acd9273b492524d3

Added to database: 08/19/2026, 13:50:58 UTC

Last enriched: 08/19/2026, 14:30:46 UTC

Last updated: 08/19/2026, 14:30:46 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses