Malicious code in ngsw-config (npm)
Description
The npm package named 'ngsw-config' version 1.0.0 contains malicious code that executes during the postinstall lifecycle script. This script collects host identifiers such as hostname, platform, architecture, Node version, package name, lifecycle name, and timestamp, then sends this data without user consent to a hardcoded external endpoint. The package name mimics Angular's legitimate tooling, likely to exploit dependency confusion in internal build systems, causing them to inadvertently leak identifying metadata.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The malicious npm package 'ngsw-config' version 1.0.0 executes a postinstall script that gathers system and environment metadata from the installer host and transmits it as JSON to a hardcoded URL (https://wxc97jnc.instances.poc.jchunt.top/ngsw-config). This behavior occurs without user consent or documentation. The package name is crafted to shadow Angular's legitimate 'ngsw-config' tool, serving as a canary for dependency confusion attacks where internal build systems mistakenly resolve this malicious package and leak sensitive identifying information to the attacker-controlled endpoint.
Potential Impact
The primary impact is unauthorized data exfiltration of host identifiers and environment details during package installation. This can lead to privacy violations and potential reconnaissance by attackers. There is no indication of further exploitation or code execution beyond data collection. No known exploits in the wild have been reported.
Mitigation Recommendations
No official patch or remediation is currently available. Users should avoid installing the 'ngsw-config' package version 1.0.0 from untrusted sources. Verify package authenticity and source before installation, especially in internal build systems. Monitor dependency resolution configurations to prevent dependency confusion attacks. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-14251
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a85b4c0acd9273b4925243f
Added to database: 08/19/2026, 13:50:56 UTC
Last enriched: 08/19/2026, 14:28:35 UTC
Last updated: 10/02/2026, 13:52:10 UTC
Views: 24
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.