Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in @marketfront/commonecommerce (npm)

0
Critical
Published: 07/02/2026 (07/02/2026, 00:00:00 UTC)
Source: GCVE Database
Product: @marketfront/commonecommerce

Description

The @marketfront/commonecommerce npm package version 7.0.0 is part of a malicious campaign involving 25 packages published within a short time frame. It contains a heavily obfuscated postinstall script that executes automatically during npm install, harvesting sensitive credentials and environment data from the host. The stolen data includes SSH keys, AWS credentials, Kubernetes configs, Docker configs, npm and git credentials, environment files, and shell history. Exfiltration occurs via encrypted HTTPS POST requests and covert DNS tunneling to a concealed command-and-control server. The package masquerades as a legitimate telemetry client for a non-existent organization, with a non-functional advertised API. No patch or remediation is currently documented.

Affected software

npmghsa
@marketfront/commonecommerce
Affected versions
=7.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/06/2026, 23:40:26 UTC

Technical Analysis

This threat involves a malicious npm package, @marketfront/commonecommerce version 7.0.0, published as part of a 25-package campaign under the @marketfront scope. The package uses a postinstall lifecycle hook to run a 162 KB obfuscated JavaScript payload that harvests a wide range of sensitive credential files and environment variables from the infected system. The harvested data is encrypted with RC4 and exfiltrated via two channels: an HTTPS POST to a dynamically assembled host and DNS-label tunneling designed to evade egress filtering. The package attempts to evade detection by inspecting runtime arguments and environment variables and delaying execution. It falsely claims to be a telemetry client for a legitimate organization, which does not exist. The actual library code is a stub, with the postinstall script being the only active malicious component. This campaign shares infrastructure and tooling with a previous campaign, indicating a persistent threat actor rotating npm scopes and maintainer identities. No official patch or remediation guidance is provided in the source data.

Potential Impact

If installed, this package compromises the host by stealing a broad range of sensitive credentials and environment information, including SSH keys, cloud service credentials, Kubernetes and Docker configs, npm and git credentials, and shell history. This data exfiltration can lead to unauthorized access to cloud resources, source code repositories, and other critical infrastructure. The use of covert DNS tunneling alongside HTTPS exfiltration increases the likelihood of bypassing network security controls. The malicious code executes automatically at install time without user interaction, increasing the risk of widespread compromise in development environments that inadvertently install this package.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix or removal is published, users should avoid installing or updating to version 7.0.0 of @marketfront/commonecommerce. Audit existing environments for the presence of this package and remove it if found. Consider blocking the @marketfront npm scope in internal package registries and monitoring for suspicious postinstall scripts in dependencies. Due to the malicious nature of the package, no legitimate use is expected, so removal is the safest course of action.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-6771
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a4c348527e9c7971960742b

Added to database: 07/06/2026, 23:04:37 UTC

Last enriched: 07/06/2026, 23:40:26 UTC

Last updated: 07/30/2026, 09:35:34 UTC

Views: 14

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses