Malicious code in @marketfront/commonecommerce (npm)
The @marketfront/commonecommerce npm package version 7.0.0 is part of a malicious campaign involving 25 packages published within a short time frame. It contains a heavily obfuscated postinstall script that executes automatically during npm install, harvesting sensitive credentials and environment data from the host. The stolen data includes SSH keys, AWS credentials, Kubernetes configs, Docker configs, npm and git credentials, environment files, and shell history. Exfiltration occurs via encrypted HTTPS POST requests and covert DNS tunneling to a concealed command-and-control server. The package masquerades as a legitimate telemetry client for a non-existent organization, with a non-functional advertised API. No patch or remediation is currently documented.
AI Analysis
Technical Summary
This threat involves a malicious npm package, @marketfront/commonecommerce version 7.0.0, published as part of a 25-package campaign under the @marketfront scope. The package uses a postinstall lifecycle hook to run a 162 KB obfuscated JavaScript payload that harvests a wide range of sensitive credential files and environment variables from the infected system. The harvested data is encrypted with RC4 and exfiltrated via two channels: an HTTPS POST to a dynamically assembled host and DNS-label tunneling designed to evade egress filtering. The package attempts to evade detection by inspecting runtime arguments and environment variables and delaying execution. It falsely claims to be a telemetry client for a legitimate organization, which does not exist. The actual library code is a stub, with the postinstall script being the only active malicious component. This campaign shares infrastructure and tooling with a previous campaign, indicating a persistent threat actor rotating npm scopes and maintainer identities. No official patch or remediation guidance is provided in the source data.
Potential Impact
If installed, this package compromises the host by stealing a broad range of sensitive credentials and environment information, including SSH keys, cloud service credentials, Kubernetes and Docker configs, npm and git credentials, and shell history. This data exfiltration can lead to unauthorized access to cloud resources, source code repositories, and other critical infrastructure. The use of covert DNS tunneling alongside HTTPS exfiltration increases the likelihood of bypassing network security controls. The malicious code executes automatically at install time without user interaction, increasing the risk of widespread compromise in development environments that inadvertently install this package.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix or removal is published, users should avoid installing or updating to version 7.0.0 of @marketfront/commonecommerce. Audit existing environments for the presence of this package and remove it if found. Consider blocking the @marketfront npm scope in internal package registries and monitoring for suspicious postinstall scripts in dependencies. Due to the malicious nature of the package, no legitimate use is expected, so removal is the safest course of action.
Malicious code in @marketfront/commonecommerce (npm)
Description
The @marketfront/commonecommerce npm package version 7.0.0 is part of a malicious campaign involving 25 packages published within a short time frame. It contains a heavily obfuscated postinstall script that executes automatically during npm install, harvesting sensitive credentials and environment data from the host. The stolen data includes SSH keys, AWS credentials, Kubernetes configs, Docker configs, npm and git credentials, environment files, and shell history. Exfiltration occurs via encrypted HTTPS POST requests and covert DNS tunneling to a concealed command-and-control server. The package masquerades as a legitimate telemetry client for a non-existent organization, with a non-functional advertised API. No patch or remediation is currently documented.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves a malicious npm package, @marketfront/commonecommerce version 7.0.0, published as part of a 25-package campaign under the @marketfront scope. The package uses a postinstall lifecycle hook to run a 162 KB obfuscated JavaScript payload that harvests a wide range of sensitive credential files and environment variables from the infected system. The harvested data is encrypted with RC4 and exfiltrated via two channels: an HTTPS POST to a dynamically assembled host and DNS-label tunneling designed to evade egress filtering. The package attempts to evade detection by inspecting runtime arguments and environment variables and delaying execution. It falsely claims to be a telemetry client for a legitimate organization, which does not exist. The actual library code is a stub, with the postinstall script being the only active malicious component. This campaign shares infrastructure and tooling with a previous campaign, indicating a persistent threat actor rotating npm scopes and maintainer identities. No official patch or remediation guidance is provided in the source data.
Potential Impact
If installed, this package compromises the host by stealing a broad range of sensitive credentials and environment information, including SSH keys, cloud service credentials, Kubernetes and Docker configs, npm and git credentials, and shell history. This data exfiltration can lead to unauthorized access to cloud resources, source code repositories, and other critical infrastructure. The use of covert DNS tunneling alongside HTTPS exfiltration increases the likelihood of bypassing network security controls. The malicious code executes automatically at install time without user interaction, increasing the risk of widespread compromise in development environments that inadvertently install this package.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix or removal is published, users should avoid installing or updating to version 7.0.0 of @marketfront/commonecommerce. Audit existing environments for the presence of this package and remove it if found. Consider blocking the @marketfront npm scope in internal package registries and monitoring for suspicious postinstall scripts in dependencies. Due to the malicious nature of the package, no legitimate use is expected, so removal is the safest course of action.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-6771
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a4c348527e9c7971960742b
Added to database: 07/06/2026, 23:04:37 UTC
Last enriched: 07/06/2026, 23:40:26 UTC
Last updated: 07/30/2026, 09:35:34 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.