Malicious code in getd-handler-api (npm)
The npm package getd-handler-api version 0.0.1 contains malicious code that collects sensitive installer environment data, including hostname, username, platform, working directory, and CI environment variables, and sends this information without consent to an external URL during installation. This unauthorized data exfiltration occurs silently and is combined with a typosquatting tactic to deceive users. The presence of this package on a system indicates a full compromise, requiring immediate secret and key rotation and package removal, although removal may not fully eradicate the compromise.
AI Analysis
Technical Summary
The getd-handler-api npm package (version 0.0.1) includes a postinstall script that collects identifying environment information from the installer's machine and sends it via HTTPS GET to an external webhook URL. This data collection is performed silently with errors suppressed, constituting unauthorized exfiltration of sensitive information. The package is a typosquat placeholder mimicking the @getd/* scope, a common namespace abuse pattern. According to the GHSA advisory, any system with this package installed should be considered fully compromised, with all secrets rotated and the package removed, though full remediation may require further incident response due to potential persistent control by attackers.
Potential Impact
Unauthorized collection and exfiltration of environment and system identifiers occur during package installation without user consent. The compromise is severe enough that affected systems are considered fully controlled by attackers, risking exposure of all stored secrets and keys. This can lead to extensive security breaches beyond the initial package installation.
Mitigation Recommendations
No official patch or fix is available for this malicious package. Immediate removal of the getd-handler-api package version 0.0.1 is required. All secrets and keys stored on the affected system should be rotated from a separate, trusted machine. Due to the potential for persistent compromise, comprehensive incident response and system remediation are recommended. Monitor for any signs of further malicious activity and consider rebuilding affected systems if necessary.
Malicious code in getd-handler-api (npm)
Description
The npm package getd-handler-api version 0.0.1 contains malicious code that collects sensitive installer environment data, including hostname, username, platform, working directory, and CI environment variables, and sends this information without consent to an external URL during installation. This unauthorized data exfiltration occurs silently and is combined with a typosquatting tactic to deceive users. The presence of this package on a system indicates a full compromise, requiring immediate secret and key rotation and package removal, although removal may not fully eradicate the compromise.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The getd-handler-api npm package (version 0.0.1) includes a postinstall script that collects identifying environment information from the installer's machine and sends it via HTTPS GET to an external webhook URL. This data collection is performed silently with errors suppressed, constituting unauthorized exfiltration of sensitive information. The package is a typosquat placeholder mimicking the @getd/* scope, a common namespace abuse pattern. According to the GHSA advisory, any system with this package installed should be considered fully compromised, with all secrets rotated and the package removed, though full remediation may require further incident response due to potential persistent control by attackers.
Potential Impact
Unauthorized collection and exfiltration of environment and system identifiers occur during package installation without user consent. The compromise is severe enough that affected systems are considered fully controlled by attackers, risking exposure of all stored secrets and keys. This can lead to extensive security breaches beyond the initial package installation.
Mitigation Recommendations
No official patch or fix is available for this malicious package. Immediate removal of the getd-handler-api package version 0.0.1 is required. All secrets and keys stored on the affected system should be rotated from a separate, trusted machine. Due to the potential for persistent compromise, comprehensive incident response and system remediation are recommended. Monitor for any signs of further malicious activity and consider rebuilding affected systems if necessary.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-5467
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-wgvw-wjqc-rg8w"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a54adee68715ace438f6c25
Added to database: 07/13/2026, 09:20:46 UTC
Last enriched: 07/13/2026, 09:49:29 UTC
Last updated: 07/31/2026, 03:16:26 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.