Malicious code in js-soul (npm)
Description
The npm package 'js-soul' version 1.0.4 contains malicious code that executes arbitrary JavaScript during module import. It reads and DES-decrypts a file disguised as an image outside the package directory using a hardcoded key, then spawns a detached Node.js process to run the decrypted code. This behavior contradicts the package's stated purpose and README claims, allowing attacker-controlled code to run with the installer's privileges.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'js-soul' npm package (version 1.0.4) includes malicious functionality in src/api/session-api.js that reads a file '../../../../public/logo.ico' outside the package directory. It decrypts this file's contents using DES with a hardcoded key 'bf497c0b9cee', then spawns a detached Node.js child process, piping the decrypted code into the interpreter's stdin. This results in execution of arbitrary code at import time, despite the package's claim that no code runs on import. The use of an unrelated error string and the disguise of executable code as an image file indicate deliberate obfuscation. Any attacker-controlled code staged at the sibling path executes with the installer's privileges, posing a significant risk.
Potential Impact
Arbitrary code execution occurs during package import, allowing attacker-controlled code to run with the privileges of the user installing the package. This can lead to full compromise of the install environment, including potential persistence, data theft, or further system compromise.
Mitigation Recommendations
No patch or remediation information is provided. Patch status is not yet confirmed — check the vendor advisory or npm repository for current remediation guidance. Until a fix is available, avoid using version 1.0.4 of 'js-soul' and consider removing it from your dependency tree.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-14477
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a8d9ae8acd9273b493e17a3
Added to database: 08/25/2026, 13:38:48 UTC
Last enriched: 09/10/2026, 18:48:05 UTC
Last updated: 10/03/2026, 15:44:11 UTC
Views: 31
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.