Malicious code in @mgor/fw-canary-3333 (npm)
The npm package @mgor/fw-canary-3333 versions 0.0.1 and 0.0.2 contains malicious code that executes a shell command during installation. This command fetches and runs attacker-controlled shell code from an external URL, contradicting the package's claim of having no install scripts or functionality.
AI Analysis
Technical Summary
The @mgor/fw-canary-3333 npm package, specifically versions 0.0.1 and 0.0.2, executes a top-level shell command in its index.js file that performs an unpinned, unverified curl request to https://fewafw.hydege.me. The response is piped directly into /bin/bash, causing arbitrary attacker-controlled code to run on the host during package installation. The package's metadata falsely claims no install scripts or dependencies, serving as a cover for this malicious behavior.
Potential Impact
Installation of the affected package versions results in execution of arbitrary shell commands controlled by an attacker. This can lead to full compromise of the host system where the package is installed, including unauthorized code execution and potential persistence or data theft.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid installing or using the @mgor/fw-canary-3333 package versions 0.0.1 and 0.0.2. Verify package integrity and source before installation, and consider using trusted package registries and tools that detect malicious packages.
Malicious code in @mgor/fw-canary-3333 (npm)
Description
The npm package @mgor/fw-canary-3333 versions 0.0.1 and 0.0.2 contains malicious code that executes a shell command during installation. This command fetches and runs attacker-controlled shell code from an external URL, contradicting the package's claim of having no install scripts or functionality.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The @mgor/fw-canary-3333 npm package, specifically versions 0.0.1 and 0.0.2, executes a top-level shell command in its index.js file that performs an unpinned, unverified curl request to https://fewafw.hydege.me. The response is piped directly into /bin/bash, causing arbitrary attacker-controlled code to run on the host during package installation. The package's metadata falsely claims no install scripts or dependencies, serving as a cover for this malicious behavior.
Potential Impact
Installation of the affected package versions results in execution of arbitrary shell commands controlled by an attacker. This can lead to full compromise of the host system where the package is installed, including unauthorized code execution and potential persistence or data theft.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid installing or using the @mgor/fw-canary-3333 package versions 0.0.1 and 0.0.2. Verify package integrity and source before installation, and consider using trusted package registries and tools that detect malicious packages.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12322
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a735730bf8831d53913cef1
Added to database: 08/05/2026, 15:30:56 UTC
Last enriched: 08/05/2026, 15:42:30 UTC
Last updated: 09/18/2026, 00:13:18 UTC
Views: 24
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.