Malicious code in @marketfront/designsystemdevtool (npm)
The @marketfront/designsystemdevtool npm package version 7.0.0 is part of a malicious campaign involving 25 packages published within a short timeframe. It contains an obfuscated postinstall script that executes automatically during npm install, harvesting sensitive credentials and environment data from the host system. The stolen data includes SSH keys, cloud credentials, Docker and Kubernetes configs, npm and git credentials, environment variables, and shell history. This data is exfiltrated via HTTPS POST requests with additional DNS tunneling fallback to attacker-controlled infrastructure. The package impersonates an internal Marketfront scope but lacks legitimate functionality, serving solely as a credential stealer. The campaign shares infrastructure and techniques with a prior malicious campaign, indicating a persistent threat actor. No official patch or remediation is currently documented.
AI Analysis
Technical Summary
The @marketfront/designsystemdevtool package (version 7.0.0) was published as part of a 25-package malicious campaign on 2026-07-01 under the npm user 'marketfront'. It contains a heavily obfuscated postinstall hook that runs automatically at npm install time, executing a credential harvester. This harvester dynamically loads core Node.js modules and reads approximately 20 sensitive credential files and environment variables, including SSH keys, AWS credentials, Kubernetes configs, Docker configs, npm and git credentials, and shell history. The collected data is compressed and exfiltrated over HTTPS with a custom header and also uses DNS tunneling as a fallback. The command-and-control server address is concealed via RC4+XOR encryption. The package is a public-registry impersonation of a private Marketfront scope and contains no legitimate library code. It performs runtime environment checks to evade debugging and instrumentation. This campaign shares tooling and infrastructure patterns with a previous malicious campaign (@emcd-vue), indicating the same threat actor rotating scopes and maintainer emails. No CVSS score or official patch is available.
Potential Impact
Systems that install this package version 7.0.0 will have sensitive credentials and environment information silently harvested and exfiltrated to attacker-controlled infrastructure during npm install. This includes private keys, cloud credentials, configuration files, environment variables (potentially containing CI tokens and internal URLs), and shell history. This can lead to credential compromise, unauthorized access to cloud and internal resources, and further system compromise. The malicious code executes automatically without user interaction beyond installing the package, increasing risk in CI/CD pipelines and developer environments.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix or removal from the npm registry is confirmed, avoid installing or updating to version 7.0.0 of @marketfront/designsystemdevtool from the public npm registry. Verify package sources carefully, especially for scoped packages that may impersonate private registries. Use private registries as intended and audit dependencies for unexpected postinstall scripts. Consider scanning existing environments for signs of this package and related malicious activity.
Malicious code in @marketfront/designsystemdevtool (npm)
Description
The @marketfront/designsystemdevtool npm package version 7.0.0 is part of a malicious campaign involving 25 packages published within a short timeframe. It contains an obfuscated postinstall script that executes automatically during npm install, harvesting sensitive credentials and environment data from the host system. The stolen data includes SSH keys, cloud credentials, Docker and Kubernetes configs, npm and git credentials, environment variables, and shell history. This data is exfiltrated via HTTPS POST requests with additional DNS tunneling fallback to attacker-controlled infrastructure. The package impersonates an internal Marketfront scope but lacks legitimate functionality, serving solely as a credential stealer. The campaign shares infrastructure and techniques with a prior malicious campaign, indicating a persistent threat actor. No official patch or remediation is currently documented.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The @marketfront/designsystemdevtool package (version 7.0.0) was published as part of a 25-package malicious campaign on 2026-07-01 under the npm user 'marketfront'. It contains a heavily obfuscated postinstall hook that runs automatically at npm install time, executing a credential harvester. This harvester dynamically loads core Node.js modules and reads approximately 20 sensitive credential files and environment variables, including SSH keys, AWS credentials, Kubernetes configs, Docker configs, npm and git credentials, and shell history. The collected data is compressed and exfiltrated over HTTPS with a custom header and also uses DNS tunneling as a fallback. The command-and-control server address is concealed via RC4+XOR encryption. The package is a public-registry impersonation of a private Marketfront scope and contains no legitimate library code. It performs runtime environment checks to evade debugging and instrumentation. This campaign shares tooling and infrastructure patterns with a previous malicious campaign (@emcd-vue), indicating the same threat actor rotating scopes and maintainer emails. No CVSS score or official patch is available.
Potential Impact
Systems that install this package version 7.0.0 will have sensitive credentials and environment information silently harvested and exfiltrated to attacker-controlled infrastructure during npm install. This includes private keys, cloud credentials, configuration files, environment variables (potentially containing CI tokens and internal URLs), and shell history. This can lead to credential compromise, unauthorized access to cloud and internal resources, and further system compromise. The malicious code executes automatically without user interaction beyond installing the package, increasing risk in CI/CD pipelines and developer environments.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix or removal from the npm registry is confirmed, avoid installing or updating to version 7.0.0 of @marketfront/designsystemdevtool from the public npm registry. Verify package sources carefully, especially for scoped packages that may impersonate private registries. Use private registries as intended and audit dependencies for unexpected postinstall scripts. Consider scanning existing environments for signs of this package and related malicious activity.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-6773
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a4c348527e9c79719607423
Added to database: 07/06/2026, 23:04:37 UTC
Last enriched: 07/06/2026, 23:40:07 UTC
Last updated: 07/23/2026, 06:11:09 UTC
Views: 16
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.