Malicious code in neverthrow-core (npm)
Description
The [email protected] package on npm is a typosquatting malicious package impersonating the legitimate neverthrow library. It contains a preinstall script that automatically executes during npm install, which downloads and runs a potentially harmful payload from an anonymous Dropbox URL without any integrity verification. The malicious code is hidden in the CommonJS bundle and not present in the ESM build, making detection harder. The package metadata is copied to appear legitimate, increasing the risk of accidental installation.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
[email protected] is a typosquatting npm package mimicking the popular neverthrow library. Its package.json defines a preinstall script that runs a function named bcryptInstall from the CommonJS bundle. This function downloads a tarball from an anonymous and mutable Dropbox link, extracts it, changes permissions, and executes the files without any signature or hash verification. The malicious payload is concealed in the CJS build and absent from the ESM build, hiding it from users inspecting the ESM entrypoint. The package metadata is copied from the legitimate neverthrow repository to impersonate an official companion package.
Potential Impact
Users who mistakenly install [email protected] may execute arbitrary code on their systems due to the preinstall script running automatically. The payload is fetched from an untrusted, mutable Dropbox URL without integrity checks, allowing an attacker to deliver any code. This can lead to system compromise or further malicious activity. The impersonation of a legitimate package increases the likelihood of accidental installation.
Mitigation Recommendations
Avoid installing [email protected]. Verify package names carefully to avoid typosquatting attacks. Since no official patch or fix exists for this malicious package, the best mitigation is to remove any installations of [email protected] and rely only on the legitimate neverthrow package. Monitor package sources and use tools that detect typosquatting or malicious npm packages.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-14283
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a85b4b4acd9273b4925154a
Added to database: 08/19/2026, 13:50:44 UTC
Last enriched: 08/19/2026, 14:15:59 UTC
Last updated: 10/02/2026, 13:51:44 UTC
Views: 26
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.