Malicious code in @marketfront/mychatspreloader (npm)
The @marketfront/mychatspreloader npm package version 7.0.0 is part of a malicious campaign involving 25 packages published within a short time frame. It contains a heavily obfuscated postinstall script that executes automatically during npm install, harvesting sensitive credential files from the user's system. The stolen data includes SSH keys, AWS credentials, Kubernetes configs, Docker configs, npm tokens, Git credentials, environment files, and shell history. The collected information is exfiltrated via encrypted HTTPS POST requests and DNS tunneling to a concealed command-and-control server. The package has no legitimate functionality and is designed solely to steal credentials under the guise of an internal scoped package. This campaign shares infrastructure and tactics with a previous malicious npm campaign, indicating a recurring threat actor.
AI Analysis
Technical Summary
The @marketfront/mychatspreloader package (version 7.0.0) is a malicious npm package published as part of a 25-package campaign under the @marketfront scope. It includes a heavily obfuscated postinstall.js script that runs automatically on npm install. This script enumerates environment variables, collects OS and user information, and reads approximately 20 sensitive credential files from common locations on Unix-like and Windows systems. The harvested data is exfiltrated via a gzip-compressed HTTPS POST request with a custom X-Secret header and via DNS resolver beaconing, using an RC4+XOR encrypted embedded configuration to conceal the command-and-control host. The package has no legitimate code or functionality and is intended solely for credential theft. The campaign reuses tooling and infrastructure from a previous @emcd-vue campaign, suggesting the same threat actor rotating npm scopes and maintainer identities.
Potential Impact
Successful installation of this package results in the theft of a wide range of sensitive credentials and configuration files from the victim's system, including SSH keys, cloud service credentials, Kubernetes configs, Docker credentials, npm tokens, Git credentials, environment variables, and shell history. This can lead to unauthorized access to source code repositories, cloud environments, container registries, and other critical infrastructure. The exfiltration methods include encrypted HTTPS POST requests and DNS tunneling, making detection and blocking more difficult. The package itself provides no legitimate functionality, so its presence indicates compromise.
Mitigation Recommendations
No official patch or remediation is available since this is a malicious package rather than a vulnerability in legitimate software. The package should be removed and blocked from use. Users and organizations should audit their npm dependencies for any @marketfront scoped packages, especially version 7.0.0 of mychatspreloader, and remove them immediately. Avoid installing packages from untrusted or unexpected scopes, especially those purporting to be internal registries without verification. Monitor for signs of credential compromise and rotate any potentially exposed credentials. Since this is not a cloud service, remediation depends on user action. Patch status is not applicable; check vendor or registry advisories for updates.
Malicious code in @marketfront/mychatspreloader (npm)
Description
The @marketfront/mychatspreloader npm package version 7.0.0 is part of a malicious campaign involving 25 packages published within a short time frame. It contains a heavily obfuscated postinstall script that executes automatically during npm install, harvesting sensitive credential files from the user's system. The stolen data includes SSH keys, AWS credentials, Kubernetes configs, Docker configs, npm tokens, Git credentials, environment files, and shell history. The collected information is exfiltrated via encrypted HTTPS POST requests and DNS tunneling to a concealed command-and-control server. The package has no legitimate functionality and is designed solely to steal credentials under the guise of an internal scoped package. This campaign shares infrastructure and tactics with a previous malicious npm campaign, indicating a recurring threat actor.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The @marketfront/mychatspreloader package (version 7.0.0) is a malicious npm package published as part of a 25-package campaign under the @marketfront scope. It includes a heavily obfuscated postinstall.js script that runs automatically on npm install. This script enumerates environment variables, collects OS and user information, and reads approximately 20 sensitive credential files from common locations on Unix-like and Windows systems. The harvested data is exfiltrated via a gzip-compressed HTTPS POST request with a custom X-Secret header and via DNS resolver beaconing, using an RC4+XOR encrypted embedded configuration to conceal the command-and-control host. The package has no legitimate code or functionality and is intended solely for credential theft. The campaign reuses tooling and infrastructure from a previous @emcd-vue campaign, suggesting the same threat actor rotating npm scopes and maintainer identities.
Potential Impact
Successful installation of this package results in the theft of a wide range of sensitive credentials and configuration files from the victim's system, including SSH keys, cloud service credentials, Kubernetes configs, Docker credentials, npm tokens, Git credentials, environment variables, and shell history. This can lead to unauthorized access to source code repositories, cloud environments, container registries, and other critical infrastructure. The exfiltration methods include encrypted HTTPS POST requests and DNS tunneling, making detection and blocking more difficult. The package itself provides no legitimate functionality, so its presence indicates compromise.
Mitigation Recommendations
No official patch or remediation is available since this is a malicious package rather than a vulnerability in legitimate software. The package should be removed and blocked from use. Users and organizations should audit their npm dependencies for any @marketfront scoped packages, especially version 7.0.0 of mychatspreloader, and remove them immediately. Avoid installing packages from untrusted or unexpected scopes, especially those purporting to be internal registries without verification. Monitor for signs of credential compromise and rotate any potentially exposed credentials. Since this is not a cloud service, remediation depends on user action. Patch status is not applicable; check vendor or registry advisories for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-6786
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a4c348427e9c797196072d8
Added to database: 07/06/2026, 23:04:36 UTC
Last enriched: 07/06/2026, 23:22:37 UTC
Last updated: 07/26/2026, 12:33:35 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.