Skip to main content

Malicious code in ngsw-config (npm)

0
Medium
Published: 08/19/2026 (08/19/2026, 04:18:35 UTC)
Source: GCVE Database
Product: ngsw-config

Description

The npm package named 'ngsw-config' version 1.0.0 contains malicious code that executes during the postinstall lifecycle script. This script collects host identifiers such as hostname, platform, architecture, Node version, package name, lifecycle name, and timestamp, then sends this data without user consent to a hardcoded external endpoint. The package name mimics Angular's legitimate tooling, likely to exploit dependency confusion in internal build systems, causing them to inadvertently leak identifying metadata.

Affected software

npmghsa
ngsw-config
Affected versions
=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/19/2026, 14:28:35 UTC

Technical Analysis

The malicious npm package 'ngsw-config' version 1.0.0 executes a postinstall script that gathers system and environment metadata from the installer host and transmits it as JSON to a hardcoded URL (https://wxc97jnc.instances.poc.jchunt.top/ngsw-config). This behavior occurs without user consent or documentation. The package name is crafted to shadow Angular's legitimate 'ngsw-config' tool, serving as a canary for dependency confusion attacks where internal build systems mistakenly resolve this malicious package and leak sensitive identifying information to the attacker-controlled endpoint.

Potential Impact

The primary impact is unauthorized data exfiltration of host identifiers and environment details during package installation. This can lead to privacy violations and potential reconnaissance by attackers. There is no indication of further exploitation or code execution beyond data collection. No known exploits in the wild have been reported.

Mitigation Recommendations

No official patch or remediation is currently available. Users should avoid installing the 'ngsw-config' package version 1.0.0 from untrusted sources. Verify package authenticity and source before installation, especially in internal build systems. Monitor dependency resolution configurations to prevent dependency confusion attacks. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-14251
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6a85b4c0acd9273b4925243f

Added to database: 08/19/2026, 13:50:56 UTC

Last enriched: 08/19/2026, 14:28:35 UTC

Last updated: 10/02/2026, 13:52:10 UTC

Views: 24

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses