Skip to main content

Malicious code in golaaa (npm)

0
Critical
Published: 08/06/2026 (08/06/2026, 12:13:09 UTC)
Source: GCVE Database
Product: golaaa

Description

The golaaa npm package version 1.0.0 contains malicious code that disables TLS certificate verification, forcibly restarts a local browser executable with remote debugging enabled, and injects scripts into browser pages to exfiltrate user data. The exfiltrated data includes page text and active editor contents, which are base64-encoded and sent to a hardcoded remote endpoint. The remote endpoint can respond with JavaScript code that is executed within the victim's browser context, enabling arbitrary code execution including on CSP-restricted pages. An embedded and obfuscated Groq API key is also sent to the attacker-controlled proxy. This behavior occurs automatically upon module load without user consent.

Affected software

npmghsa
golaaa
Affected versions
=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/19/2026, 16:03:25 UTC

Technical Analysis

The golaaa npm package (version 1.0.0) contains a malicious main module (cdp_inject.js) that disables TLS certificate verification globally by setting process.env.NODE_TLS_REJECT_UNAUTHORIZED='0'. It forcibly terminates and restarts a local browser executable located at %USERPROFILE%\AppData\Local\Programs\testpad\testpad.exe with remote debugging enabled on port 9222. The package connects to this browser via the Chrome DevTools Protocol and injects a script into every attached page. This script captures the document body text and active editor contents on user gestures, base64-encodes this data, and sends it via POST to a hardcoded Cloudflare Workers proxy endpoint (https://ai-script.test0ing7.workers.dev/), which forwards to Groq. The remote response is executed as JavaScript in the browser context, allowing arbitrary code execution including on pages with Content Security Policy restrictions. The package also embeds an obfuscated Groq API key, which it sends to the same proxy. This malicious behavior starts immediately upon requiring the module, without any opt-in or configuration.

Potential Impact

This malicious package compromises the confidentiality and integrity of user data by exfiltrating sensitive page content and editor inputs to a remote attacker-controlled server. It disables TLS verification, increasing the risk of man-in-the-middle attacks. The injected code enables arbitrary JavaScript execution in the victim's browser sessions, including on CSP-restricted pages, potentially allowing full browser session compromise and keystroke injection. This can lead to credential theft, session hijacking, and further compromise of the victim's environment.

Mitigation Recommendations

No official patch or remediation is currently documented. Users should immediately remove the golaaa package version 1.0.0 from their environments and avoid installing or requiring this package. Since the malicious behavior activates on module load without opt-in, uninstalling and replacing the package with a trusted alternative is critical. Monitor for any unauthorized browser processes (such as testpad.exe) running with remote debugging enabled and terminate them. Check for any suspicious network connections to the hardcoded exfiltration endpoint and block them at the network perimeter. Patch status is not yet confirmed — check the vendor advisory or trusted security sources for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13392
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6a74cf94bf8831d5391af7d2

Added to database: 08/06/2026, 18:16:52 UTC

Last enriched: 08/19/2026, 16:03:25 UTC

Last updated: 09/21/2026, 06:53:36 UTC

Views: 42

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses