Malicious code in getd-ui-library (npm)
The npm package 'getd-ui-library' version 0.0.1 contains malicious code that executes a post-install script sending identifying telemetry from the installer's machine to an external anonymous request-capture service. This includes hostname, username, platform, current working directory, and CI environment variables. The package name mimics a legitimate scoped package to trick developers into installing it. Installation of this package can lead to full compromise of the affected computer, requiring immediate secret and key rotation and package removal.
AI Analysis
Technical Summary
The 'getd-ui-library' npm package (version 0.0.1) includes a postinstall.js script that runs unconditionally upon installation. This script sends an HTTPS GET request to a hardcoded webhook.site URL, transmitting sensitive telemetry such as the installer's hostname, username, platform, current working directory, and continuous integration environment variables. The package name is designed to impersonate the legitimate '@getd/ui-library' scoped package, increasing the likelihood of accidental installation. According to the GHSA-malware source, any system with this package installed or running should be considered fully compromised, with all secrets and keys rotated immediately. Removal of the package alone may not eliminate all malicious software introduced.
Potential Impact
Installation of this package results in exfiltration of sensitive system and environment information to an external attacker-controlled endpoint. The attacker gains telemetry useful for follow-on targeting, including CI build agent fingerprinting and developer host enumeration. The compromise is severe enough that the affected system should be treated as fully compromised, with all stored secrets and keys considered exposed. There is no guarantee that removing the package removes all malicious artifacts, indicating potential persistence or additional malware installation.
Mitigation Recommendations
No official patch or fix is available. Immediate removal of the 'getd-ui-library' package version 0.0.1 is required. All secrets, credentials, and keys stored on the affected machine should be rotated from a separate, uncompromised device. Due to the high likelihood of full system compromise, consider rebuilding the affected system from a known good state. Exercise caution to avoid installing similarly named malicious packages by verifying package scope and source before installation.
Malicious code in getd-ui-library (npm)
Description
The npm package 'getd-ui-library' version 0.0.1 contains malicious code that executes a post-install script sending identifying telemetry from the installer's machine to an external anonymous request-capture service. This includes hostname, username, platform, current working directory, and CI environment variables. The package name mimics a legitimate scoped package to trick developers into installing it. Installation of this package can lead to full compromise of the affected computer, requiring immediate secret and key rotation and package removal.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'getd-ui-library' npm package (version 0.0.1) includes a postinstall.js script that runs unconditionally upon installation. This script sends an HTTPS GET request to a hardcoded webhook.site URL, transmitting sensitive telemetry such as the installer's hostname, username, platform, current working directory, and continuous integration environment variables. The package name is designed to impersonate the legitimate '@getd/ui-library' scoped package, increasing the likelihood of accidental installation. According to the GHSA-malware source, any system with this package installed or running should be considered fully compromised, with all secrets and keys rotated immediately. Removal of the package alone may not eliminate all malicious software introduced.
Potential Impact
Installation of this package results in exfiltration of sensitive system and environment information to an external attacker-controlled endpoint. The attacker gains telemetry useful for follow-on targeting, including CI build agent fingerprinting and developer host enumeration. The compromise is severe enough that the affected system should be treated as fully compromised, with all stored secrets and keys considered exposed. There is no guarantee that removing the package removes all malicious artifacts, indicating potential persistence or additional malware installation.
Mitigation Recommendations
No official patch or fix is available. Immediate removal of the 'getd-ui-library' package version 0.0.1 is required. All secrets, credentials, and keys stored on the affected machine should be rotated from a separate, uncompromised device. Due to the high likelihood of full system compromise, consider rebuilding the affected system from a known good state. Exercise caution to avoid installing similarly named malicious packages by verifying package scope and source before installation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-5471
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-8h8q-6m6x-v8vv"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a54adee68715ace438f6c15
Added to database: 07/13/2026, 09:20:46 UTC
Last enriched: 07/13/2026, 09:48:59 UTC
Last updated: 07/25/2026, 15:22:26 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.