Skip to main content

Malicious code in neverthrow-core (npm)

0
High
Published: 08/19/2026 (08/19/2026, 07:58:06 UTC)
Source: GCVE Database
Product: neverthrow-core

Description

The [email protected] package on npm is a typosquatting malicious package impersonating the legitimate neverthrow library. It contains a preinstall script that automatically executes during npm install, which downloads and runs a potentially harmful payload from an anonymous Dropbox URL without any integrity verification. The malicious code is hidden in the CommonJS bundle and not present in the ESM build, making detection harder. The package metadata is copied to appear legitimate, increasing the risk of accidental installation.

Affected software

npmghsa
neverthrow-core
Affected versions
=1.1.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/19/2026, 14:15:59 UTC

Technical Analysis

[email protected] is a typosquatting npm package mimicking the popular neverthrow library. Its package.json defines a preinstall script that runs a function named bcryptInstall from the CommonJS bundle. This function downloads a tarball from an anonymous and mutable Dropbox link, extracts it, changes permissions, and executes the files without any signature or hash verification. The malicious payload is concealed in the CJS build and absent from the ESM build, hiding it from users inspecting the ESM entrypoint. The package metadata is copied from the legitimate neverthrow repository to impersonate an official companion package.

Potential Impact

Users who mistakenly install [email protected] may execute arbitrary code on their systems due to the preinstall script running automatically. The payload is fetched from an untrusted, mutable Dropbox URL without integrity checks, allowing an attacker to deliver any code. This can lead to system compromise or further malicious activity. The impersonation of a legitimate package increases the likelihood of accidental installation.

Mitigation Recommendations

Avoid installing [email protected]. Verify package names carefully to avoid typosquatting attacks. Since no official patch or fix exists for this malicious package, the best mitigation is to remove any installations of [email protected] and rely only on the legitimate neverthrow package. Monitor package sources and use tools that detect typosquatting or malicious npm packages.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-14283
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6a85b4b4acd9273b4925154a

Added to database: 08/19/2026, 13:50:44 UTC

Last enriched: 08/19/2026, 14:15:59 UTC

Last updated: 10/02/2026, 13:51:44 UTC

Views: 26

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses