Malicious code in @marketfront/digitalherobannercarousel (npm)
The @marketfront/digitalherobannercarousel npm package version 7.0.0 is part of a malicious campaign involving 25 packages published under the @marketfront scope. It contains a heavily obfuscated postinstall script that executes automatically during npm install, harvesting sensitive credential files from the user's environment and exfiltrating them via encrypted HTTPS POST requests and DNS queries to a concealed command-and-control server. The package has no legitimate library functionality and is designed as a dependency-confusion lure. The campaign shares infrastructure and tactics with a previous malicious campaign, indicating a persistent threat actor.
AI Analysis
Technical Summary
@marketfront/[email protected] is a malicious npm package published in a batch campaign under the @marketfront scope. It includes a postinstall hook executing a large obfuscated script that dynamically loads Node.js modules and reads approximately 20 sensitive credential files such as SSH keys, AWS credentials, Kubernetes configs, Docker configs, npm tokens, and environment files. The harvested data is compressed, encrypted, and exfiltrated over HTTPS POST requests with custom headers and via DNS resolution queries to evade detection. The command-and-control server address is concealed with RC4 and XOR encryption. The payload also fingerprints the host environment and attempts to detect debugging or sandbox environments to avoid analysis. This package contains no real functional code and is intended solely for credential theft. The campaign is linked to a known actor previously using the @emcd-vue scope.
Potential Impact
If installed, this package compromises the confidentiality of a wide range of sensitive credentials and configuration files on the host system. This can lead to unauthorized access to cloud services, source code repositories, container registries, and other critical infrastructure. The exfiltration methods are designed to evade network detection, increasing the risk of stealthy data theft. The presence of environment fingerprinting and anti-debugging measures indicates a sophisticated threat actor aiming to maintain persistence and avoid analysis.
Mitigation Recommendations
Avoid installing the @marketfront/digitalherobannercarousel package version 7.0.0 or any other packages from the @marketfront scope published on 2026-07-01. Remove any installations of this package immediately. Since no official patch or remediation is available, rely on blocking or auditing dependencies from untrusted or unknown scopes. Use strict package source verification and supply chain security practices to prevent dependency confusion attacks. Monitor for suspicious postinstall scripts in npm packages. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for updates.
Malicious code in @marketfront/digitalherobannercarousel (npm)
Description
The @marketfront/digitalherobannercarousel npm package version 7.0.0 is part of a malicious campaign involving 25 packages published under the @marketfront scope. It contains a heavily obfuscated postinstall script that executes automatically during npm install, harvesting sensitive credential files from the user's environment and exfiltrating them via encrypted HTTPS POST requests and DNS queries to a concealed command-and-control server. The package has no legitimate library functionality and is designed as a dependency-confusion lure. The campaign shares infrastructure and tactics with a previous malicious campaign, indicating a persistent threat actor.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
@marketfront/[email protected] is a malicious npm package published in a batch campaign under the @marketfront scope. It includes a postinstall hook executing a large obfuscated script that dynamically loads Node.js modules and reads approximately 20 sensitive credential files such as SSH keys, AWS credentials, Kubernetes configs, Docker configs, npm tokens, and environment files. The harvested data is compressed, encrypted, and exfiltrated over HTTPS POST requests with custom headers and via DNS resolution queries to evade detection. The command-and-control server address is concealed with RC4 and XOR encryption. The payload also fingerprints the host environment and attempts to detect debugging or sandbox environments to avoid analysis. This package contains no real functional code and is intended solely for credential theft. The campaign is linked to a known actor previously using the @emcd-vue scope.
Potential Impact
If installed, this package compromises the confidentiality of a wide range of sensitive credentials and configuration files on the host system. This can lead to unauthorized access to cloud services, source code repositories, container registries, and other critical infrastructure. The exfiltration methods are designed to evade network detection, increasing the risk of stealthy data theft. The presence of environment fingerprinting and anti-debugging measures indicates a sophisticated threat actor aiming to maintain persistence and avoid analysis.
Mitigation Recommendations
Avoid installing the @marketfront/digitalherobannercarousel package version 7.0.0 or any other packages from the @marketfront scope published on 2026-07-01. Remove any installations of this package immediately. Since no official patch or remediation is available, rely on blocking or auditing dependencies from untrusted or unknown scopes. Use strict package source verification and supply chain security practices to prevent dependency confusion attacks. Monitor for suspicious postinstall scripts in npm packages. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-6775
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a4c348427e9c797196072fd
Added to database: 07/06/2026, 23:04:36 UTC
Last enriched: 07/06/2026, 23:08:37 UTC
Last updated: 07/30/2026, 17:41:11 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.