Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in golaaa (npm)

0
Critical
Published: 08/06/2026 (08/06/2026, 12:13:09 UTC)
Source: GCVE Database
Product: golaaa

Description

The golaaa npm package version 1.0.0 contains malicious code that launches a local browser with remote debugging enabled and disables Content Security Policy. It installs a persistent script that intercepts window.fetch calls, logs keystrokes, and captures page content, which is then encoded and sent to a hardcoded external endpoint controlled by the attacker. The package conceals API keys and the data exfiltration destination, indicating deliberate obfuscation and unauthorized data relay.

Affected software

npmghsa
golaaa
Affected versions
=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/06/2026, 18:46:12 UTC

Technical Analysis

The golaaa npm package (version 1.0.0) includes malicious functionality that launches a local browser instance with remote debugging on port 9222 and disables Content Security Policy protections. It injects a persistent script via the Chrome DevTools Protocol that intercepts network fetch requests, logs user keystrokes, and captures the contents of the document body and active elements. This captured data is base64-encoded and sent via POST requests to a hardcoded Cloudflare Worker endpoint (https://ai-script.test0ing7.workers.dev/), which is not the package's documented inference provider. The package also obfuscates two API keys using XOR and base64 encoding, reconstructing them at runtime, indicating an attempt to conceal the data exfiltration mechanism and credentials from static analysis. There is no configuration option to change the data exfiltration endpoint, confirming the malicious intent.

Potential Impact

Users of golaaa version 1.0.0 are at risk of sensitive data leakage, including keystrokes and page content, to an attacker-controlled server. This compromises confidentiality and privacy, potentially exposing sensitive information entered or displayed in the browser instance launched by the package. The obfuscation of credentials and hardcoded exfiltration endpoint suggests deliberate concealment of malicious activity.

Mitigation Recommendations

No official patch or remediation is currently documented for this malicious package version. Users should immediately discontinue use of golaaa version 1.0.0 and remove it from their environments. Avoid installing or running this package. Monitor for any unauthorized data exfiltration activity related to the described endpoint. Since this is a malicious package, the best mitigation is to avoid using it entirely.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13392
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a74cf94bf8831d5391af7d2

Added to database: 08/06/2026, 18:16:52 UTC

Last enriched: 08/06/2026, 18:46:12 UTC

Last updated: 08/06/2026, 23:38:26 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses