Malicious code in gaarf-node-bq (npm)
The npm package 'gaarf-node-bq' version 1.0.0 is a malicious typosquatting package targeting the internal 'gaarf' package used by Google Ads API report fetcher. It contains a postinstall script that collects host metadata such as hostname, platform, architecture, Node.js version, package name, and npm lifecycle event, then sends this data without user consent to a hardcoded external endpoint. The package itself provides no legitimate functionality and acts as a canary for dependency confusion attacks.
AI Analysis
Technical Summary
The 'gaarf-node-bq' npm package (version 1.0.0) is a malicious package designed for dependency confusion or typosquatting attacks. It mimics the internal 'gaarf' package to trick users or automated systems into installing it from the public npm registry instead of the intended private package. Upon installation, its postinstall lifecycle script collects host identifiers including os.hostname(), platform, architecture, Node.js version, package name, and npm lifecycle event, then exfiltrates this information as JSON to a hardcoded external URL (https://yu7pug2j.instances.poc.jchunt.top/gaarf-node-bq). The package contains no real functionality beyond this data collection and exfiltration, making it a privacy and security risk for any environment where it is mistakenly installed.
Potential Impact
Hosts that inadvertently install 'gaarf-node-bq' version 1.0.0 will have system metadata and environment details sent without consent to an external attacker-controlled endpoint. This could lead to information leakage about the host environment, which may be used for further targeted attacks or reconnaissance. There is no indication of additional payloads or direct system compromise beyond this data exfiltration.
Mitigation Recommendations
No official patch or remediation is available since this is a malicious package published to the public npm registry. The primary mitigation is to ensure that package resolution correctly points to the intended private 'gaarf' package and to audit dependencies for typosquatting or dependency confusion risks. Avoid installing packages with names similar to internal private packages from public registries. Monitor package sources and use package allowlists or scoped registries to prevent accidental installation of malicious typosquat packages.
Malicious code in gaarf-node-bq (npm)
Description
The npm package 'gaarf-node-bq' version 1.0.0 is a malicious typosquatting package targeting the internal 'gaarf' package used by Google Ads API report fetcher. It contains a postinstall script that collects host metadata such as hostname, platform, architecture, Node.js version, package name, and npm lifecycle event, then sends this data without user consent to a hardcoded external endpoint. The package itself provides no legitimate functionality and acts as a canary for dependency confusion attacks.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'gaarf-node-bq' npm package (version 1.0.0) is a malicious package designed for dependency confusion or typosquatting attacks. It mimics the internal 'gaarf' package to trick users or automated systems into installing it from the public npm registry instead of the intended private package. Upon installation, its postinstall lifecycle script collects host identifiers including os.hostname(), platform, architecture, Node.js version, package name, and npm lifecycle event, then exfiltrates this information as JSON to a hardcoded external URL (https://yu7pug2j.instances.poc.jchunt.top/gaarf-node-bq). The package contains no real functionality beyond this data collection and exfiltration, making it a privacy and security risk for any environment where it is mistakenly installed.
Potential Impact
Hosts that inadvertently install 'gaarf-node-bq' version 1.0.0 will have system metadata and environment details sent without consent to an external attacker-controlled endpoint. This could lead to information leakage about the host environment, which may be used for further targeted attacks or reconnaissance. There is no indication of additional payloads or direct system compromise beyond this data exfiltration.
Mitigation Recommendations
No official patch or remediation is available since this is a malicious package published to the public npm registry. The primary mitigation is to ensure that package resolution correctly points to the intended private 'gaarf' package and to audit dependencies for typosquatting or dependency confusion risks. Avoid installing packages with names similar to internal private packages from public registries. Monitor package sources and use package allowlists or scoped registries to prevent accidental installation of malicious typosquat packages.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-14239
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a85b4c2acd9273b492524d3
Added to database: 08/19/2026, 13:50:58 UTC
Last enriched: 08/19/2026, 14:30:46 UTC
Last updated: 08/19/2026, 14:30:46 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.