Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in @marketfront/mychatspreloader (npm)

0
Critical
Published: 07/02/2026 (07/02/2026, 00:00:00 UTC)
Source: GCVE Database
Product: @marketfront/mychatspreloader

Description

The @marketfront/mychatspreloader npm package version 7.0.0 is part of a malicious campaign involving 25 packages published within a short time frame. It contains a heavily obfuscated postinstall script that executes automatically during npm install, harvesting sensitive credential files from the user's system. The stolen data includes SSH keys, AWS credentials, Kubernetes configs, Docker configs, npm tokens, Git credentials, environment files, and shell history. The collected information is exfiltrated via encrypted HTTPS POST requests and DNS tunneling to a concealed command-and-control server. The package has no legitimate functionality and is designed solely to steal credentials under the guise of an internal scoped package. This campaign shares infrastructure and tactics with a previous malicious npm campaign, indicating a recurring threat actor.

Affected software

npmghsa
@marketfront/mychatspreloader
Affected versions
=7.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/06/2026, 23:22:37 UTC

Technical Analysis

The @marketfront/mychatspreloader package (version 7.0.0) is a malicious npm package published as part of a 25-package campaign under the @marketfront scope. It includes a heavily obfuscated postinstall.js script that runs automatically on npm install. This script enumerates environment variables, collects OS and user information, and reads approximately 20 sensitive credential files from common locations on Unix-like and Windows systems. The harvested data is exfiltrated via a gzip-compressed HTTPS POST request with a custom X-Secret header and via DNS resolver beaconing, using an RC4+XOR encrypted embedded configuration to conceal the command-and-control host. The package has no legitimate code or functionality and is intended solely for credential theft. The campaign reuses tooling and infrastructure from a previous @emcd-vue campaign, suggesting the same threat actor rotating npm scopes and maintainer identities.

Potential Impact

Successful installation of this package results in the theft of a wide range of sensitive credentials and configuration files from the victim's system, including SSH keys, cloud service credentials, Kubernetes configs, Docker credentials, npm tokens, Git credentials, environment variables, and shell history. This can lead to unauthorized access to source code repositories, cloud environments, container registries, and other critical infrastructure. The exfiltration methods include encrypted HTTPS POST requests and DNS tunneling, making detection and blocking more difficult. The package itself provides no legitimate functionality, so its presence indicates compromise.

Mitigation Recommendations

No official patch or remediation is available since this is a malicious package rather than a vulnerability in legitimate software. The package should be removed and blocked from use. Users and organizations should audit their npm dependencies for any @marketfront scoped packages, especially version 7.0.0 of mychatspreloader, and remove them immediately. Avoid installing packages from untrusted or unexpected scopes, especially those purporting to be internal registries without verification. Monitor for signs of credential compromise and rotate any potentially exposed credentials. Since this is not a cloud service, remediation depends on user action. Patch status is not applicable; check vendor or registry advisories for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-6786
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a4c348427e9c797196072d8

Added to database: 07/06/2026, 23:04:36 UTC

Last enriched: 07/06/2026, 23:22:37 UTC

Last updated: 07/26/2026, 12:33:35 UTC

Views: 11

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses