Malicious code in node-array-plus (npm)
The node-array-plus npm package versions 1.0.9 and 1.1.9 contain malicious code that executes remote payloads upon import. The package is heavily obfuscated and, when required, contacts a hardcoded IPv4 address to download an AES-256-CBC encrypted payload, which it decrypts and executes on the local machine. The package exposes no legitimate functionality and is designed solely to drop and run remote code stealthily.
AI Analysis
Technical Summary
The node-array-plus package (versions 1.0.9 and 1.1.9) contains obfuscated malicious code that, upon being imported, constructs a hardcoded IPv4 endpoint and performs an HTTP GET request to retrieve an encrypted payload. This payload is decrypted using AES-256-CBC with a key derived from MD5 and an IV from the response, then written to a file in the user's home directory and executed via child_process with hidden windows and the working directory set to the home directory. The package has no legitimate API or exported functionality, indicating its sole purpose is to execute remote code on the installer's machine. The obfuscation techniques conceal the destination and the decrypt-drop-execute chain, complicating detection.
Potential Impact
This malicious package can execute arbitrary code on the victim's machine with the privileges of the user running the Node.js process. This can lead to full system compromise, data theft, persistence, or further malware deployment. Because the code runs automatically upon import without user interaction, any project depending on these versions of node-array-plus is at risk of silent remote code execution.
Mitigation Recommendations
No official patch or remediation is currently available. Users should immediately remove versions 1.0.9 and 1.1.9 of node-array-plus from their projects and avoid installing or importing this package. Audit dependencies for this package and replace it with trusted alternatives. Monitor for any unexpected files or processes originating from the user's home directory. Since the package is malicious by design, uninstalling and removing all traces is critical.
Malicious code in node-array-plus (npm)
Description
The node-array-plus npm package versions 1.0.9 and 1.1.9 contain malicious code that executes remote payloads upon import. The package is heavily obfuscated and, when required, contacts a hardcoded IPv4 address to download an AES-256-CBC encrypted payload, which it decrypts and executes on the local machine. The package exposes no legitimate functionality and is designed solely to drop and run remote code stealthily.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The node-array-plus package (versions 1.0.9 and 1.1.9) contains obfuscated malicious code that, upon being imported, constructs a hardcoded IPv4 endpoint and performs an HTTP GET request to retrieve an encrypted payload. This payload is decrypted using AES-256-CBC with a key derived from MD5 and an IV from the response, then written to a file in the user's home directory and executed via child_process with hidden windows and the working directory set to the home directory. The package has no legitimate API or exported functionality, indicating its sole purpose is to execute remote code on the installer's machine. The obfuscation techniques conceal the destination and the decrypt-drop-execute chain, complicating detection.
Potential Impact
This malicious package can execute arbitrary code on the victim's machine with the privileges of the user running the Node.js process. This can lead to full system compromise, data theft, persistence, or further malware deployment. Because the code runs automatically upon import without user interaction, any project depending on these versions of node-array-plus is at risk of silent remote code execution.
Defensive Guidance
No official patch or remediation is currently available. Users should immediately remove versions 1.0.9 and 1.1.9 of node-array-plus from their projects and avoid installing or importing this package. Audit dependencies for this package and replace it with trusted alternatives. Monitor for any unexpected files or processes originating from the user's home directory. Since the package is malicious by design, uninstalling and removing all traces is critical.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-11142
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a735741bf8831d539157557
Added to database: 08/05/2026, 15:31:13 UTC
Last enriched: 08/05/2026, 17:04:06 UTC
Last updated: 08/05/2026, 17:04:06 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.