Malicious code in @ghost_debugger/nanocache (npm)
The npm package @ghost_debugger/nanocache version 0.1.1 contains malicious code that launches a hidden Windows executable as a background process upon import or require. This executable acts as a WebSocket-based remote agent, allowing persistent remote control over the infected machine under the guise of a cache library. The executable is not built from the package source and is opaque to the user, enabling stealthy operation.
AI Analysis
Technical Summary
The @ghost_debugger/nanocache npm package (version 0.1.1) includes a bundled 1.1 MB Windows executable (vendor/nanocache.exe) that is launched as a detached, hidden background process when the package is imported or required. This executable is inconsistent with the package's declared purpose as an in-memory cache and is not built from the provided source code. Analysis of strings within the executable reveals WebSocket-related commands, indicating it functions as a remote agent controlled by a remote party. The package README describes the executable as a drop-in slot for arbitrary Windows executables, confirming the package's role as a generic launcher for malicious code. This results in persistent, covert remote access on Windows hosts where the package is installed.
Potential Impact
Installing or importing this package on a Windows system results in a hidden native process that provides a remote attacker with persistent control over the machine. This can lead to unauthorized access, potential data compromise, and further malicious activity under the cover of a legitimate cache library.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid installing or importing @ghost_debugger/nanocache version 0.1.1. Conduct thorough audits of dependencies and remove this package from any environments where it is present. Monitor for suspicious processes named nanocache.exe on Windows hosts. Patch status is not yet confirmed — check the vendor advisory or trusted security sources for updates.
Malicious code in @ghost_debugger/nanocache (npm)
Description
The npm package @ghost_debugger/nanocache version 0.1.1 contains malicious code that launches a hidden Windows executable as a background process upon import or require. This executable acts as a WebSocket-based remote agent, allowing persistent remote control over the infected machine under the guise of a cache library. The executable is not built from the package source and is opaque to the user, enabling stealthy operation.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The @ghost_debugger/nanocache npm package (version 0.1.1) includes a bundled 1.1 MB Windows executable (vendor/nanocache.exe) that is launched as a detached, hidden background process when the package is imported or required. This executable is inconsistent with the package's declared purpose as an in-memory cache and is not built from the provided source code. Analysis of strings within the executable reveals WebSocket-related commands, indicating it functions as a remote agent controlled by a remote party. The package README describes the executable as a drop-in slot for arbitrary Windows executables, confirming the package's role as a generic launcher for malicious code. This results in persistent, covert remote access on Windows hosts where the package is installed.
Potential Impact
Installing or importing this package on a Windows system results in a hidden native process that provides a remote attacker with persistent control over the machine. This can lead to unauthorized access, potential data compromise, and further malicious activity under the cover of a legitimate cache library.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid installing or importing @ghost_debugger/nanocache version 0.1.1. Conduct thorough audits of dependencies and remove this package from any environments where it is present. Monitor for suspicious processes named nanocache.exe on Windows hosts. Patch status is not yet confirmed — check the vendor advisory or trusted security sources for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-14046
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a7ff5f6bf8831d5398800b2
Added to database: 08/15/2026, 05:15:34 UTC
Last enriched: 08/15/2026, 05:42:17 UTC
Last updated: 08/15/2026, 07:57:30 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.