Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in @marketfront/designsystemdevtool (npm)

0
Critical
Published: 07/02/2026 (07/02/2026, 00:00:00 UTC)
Source: GCVE Database
Product: @marketfront/designsystemdevtool

Description

The @marketfront/designsystemdevtool npm package version 7.0.0 is part of a malicious campaign involving 25 packages published within a short timeframe. It contains an obfuscated postinstall script that executes automatically during npm install, harvesting sensitive credentials and environment data from the host system. The stolen data includes SSH keys, cloud credentials, Docker and Kubernetes configs, npm and git credentials, environment variables, and shell history. This data is exfiltrated via HTTPS POST requests with additional DNS tunneling fallback to attacker-controlled infrastructure. The package impersonates an internal Marketfront scope but lacks legitimate functionality, serving solely as a credential stealer. The campaign shares infrastructure and techniques with a prior malicious campaign, indicating a persistent threat actor. No official patch or remediation is currently documented.

Affected software

npmghsa
@marketfront/designsystemdevtool
Affected versions
=7.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/06/2026, 23:40:07 UTC

Technical Analysis

The @marketfront/designsystemdevtool package (version 7.0.0) was published as part of a 25-package malicious campaign on 2026-07-01 under the npm user 'marketfront'. It contains a heavily obfuscated postinstall hook that runs automatically at npm install time, executing a credential harvester. This harvester dynamically loads core Node.js modules and reads approximately 20 sensitive credential files and environment variables, including SSH keys, AWS credentials, Kubernetes configs, Docker configs, npm and git credentials, and shell history. The collected data is compressed and exfiltrated over HTTPS with a custom header and also uses DNS tunneling as a fallback. The command-and-control server address is concealed via RC4+XOR encryption. The package is a public-registry impersonation of a private Marketfront scope and contains no legitimate library code. It performs runtime environment checks to evade debugging and instrumentation. This campaign shares tooling and infrastructure patterns with a previous malicious campaign (@emcd-vue), indicating the same threat actor rotating scopes and maintainer emails. No CVSS score or official patch is available.

Potential Impact

Systems that install this package version 7.0.0 will have sensitive credentials and environment information silently harvested and exfiltrated to attacker-controlled infrastructure during npm install. This includes private keys, cloud credentials, configuration files, environment variables (potentially containing CI tokens and internal URLs), and shell history. This can lead to credential compromise, unauthorized access to cloud and internal resources, and further system compromise. The malicious code executes automatically without user interaction beyond installing the package, increasing risk in CI/CD pipelines and developer environments.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix or removal from the npm registry is confirmed, avoid installing or updating to version 7.0.0 of @marketfront/designsystemdevtool from the public npm registry. Verify package sources carefully, especially for scoped packages that may impersonate private registries. Use private registries as intended and audit dependencies for unexpected postinstall scripts. Consider scanning existing environments for signs of this package and related malicious activity.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-6773
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a4c348527e9c79719607423

Added to database: 07/06/2026, 23:04:37 UTC

Last enriched: 07/06/2026, 23:40:07 UTC

Last updated: 07/23/2026, 06:11:09 UTC

Views: 16

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses