Malicious code in node-fsagent (npm)
The node-fsagent npm package contains malicious code that archives the host's /root/.codex directory, splits the archive into chunks, and exfiltrates the data by publishing these chunks as sequential npm package versions using a reconstructed npm registry authentication token. The token is embedded and reconstructed at runtime, granting publish rights to the attacker's npm account. The package's main entry is empty and does not auto-execute the malicious script; the harmful behavior occurs only if the archive-sender.js script is run directly. The package has no legitimate functionality and serves solely as a covert data exfiltration and credential distribution tool.
AI Analysis
Technical Summary
The node-fsagent npm package (versions =1.0.0, =1.0.4, =1.0.8, =1.1.1, =1.1.2, =1.1.3, =1.2.0, =1.2.1, =1.2.2) contains a malicious script named archive-sender.js that archives the /root/.codex directory on the host, splits the archive into approximately 200MB chunks, and exfiltrates these chunks by publishing them as sequential versions of the node-fsagent package on the public npm registry. The script reconstructs an npm registry authentication token at runtime by XOR operations on embedded byte arrays, then sets this token in the local npm config to gain publish rights. This mechanism allows covert data exfiltration via the npm registry and also distributes credentials that enable republishing under the attacker's npm account. The package's main entry point is empty, and no lifecycle scripts trigger the malicious code automatically; it only executes if the archive-sender.js script is invoked explicitly. The package advertises no legitimate functionality and is solely designed for malicious purposes.
Potential Impact
The malicious package enables covert exfiltration of potentially sensitive data from the host's /root/.codex directory by publishing it in chunks to the public npm registry. Additionally, the embedded authentication token grants publish rights to the attacker's npm account, allowing them to republish the node-fsagent package or other packages owned by that account, potentially facilitating further supply chain attacks or malicious package updates. There is no automatic execution of the malicious code upon installation or require, limiting exploitation to manual invocation of the script.
Mitigation Recommendations
No official patch or remediation is currently documented for this malicious package. Users should avoid installing or using the node-fsagent package in any of the affected versions. Since the malicious behavior only triggers when the archive-sender.js script is run directly, not on install or require, avoid executing any scripts from this package. Review and revoke any npm registry tokens that may have been compromised due to this package. Monitor npm accounts for unauthorized publishing activity. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for current remediation guidance.
Malicious code in node-fsagent (npm)
Description
The node-fsagent npm package contains malicious code that archives the host's /root/.codex directory, splits the archive into chunks, and exfiltrates the data by publishing these chunks as sequential npm package versions using a reconstructed npm registry authentication token. The token is embedded and reconstructed at runtime, granting publish rights to the attacker's npm account. The package's main entry is empty and does not auto-execute the malicious script; the harmful behavior occurs only if the archive-sender.js script is run directly. The package has no legitimate functionality and serves solely as a covert data exfiltration and credential distribution tool.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The node-fsagent npm package (versions =1.0.0, =1.0.4, =1.0.8, =1.1.1, =1.1.2, =1.1.3, =1.2.0, =1.2.1, =1.2.2) contains a malicious script named archive-sender.js that archives the /root/.codex directory on the host, splits the archive into approximately 200MB chunks, and exfiltrates these chunks by publishing them as sequential versions of the node-fsagent package on the public npm registry. The script reconstructs an npm registry authentication token at runtime by XOR operations on embedded byte arrays, then sets this token in the local npm config to gain publish rights. This mechanism allows covert data exfiltration via the npm registry and also distributes credentials that enable republishing under the attacker's npm account. The package's main entry point is empty, and no lifecycle scripts trigger the malicious code automatically; it only executes if the archive-sender.js script is invoked explicitly. The package advertises no legitimate functionality and is solely designed for malicious purposes.
Potential Impact
The malicious package enables covert exfiltration of potentially sensitive data from the host's /root/.codex directory by publishing it in chunks to the public npm registry. Additionally, the embedded authentication token grants publish rights to the attacker's npm account, allowing them to republish the node-fsagent package or other packages owned by that account, potentially facilitating further supply chain attacks or malicious package updates. There is no automatic execution of the malicious code upon installation or require, limiting exploitation to manual invocation of the script.
Mitigation Recommendations
No official patch or remediation is currently documented for this malicious package. Users should avoid installing or using the node-fsagent package in any of the affected versions. Since the malicious behavior only triggers when the archive-sender.js script is run directly, not on install or require, avoid executing any scripts from this package. Review and revoke any npm registry tokens that may have been compromised due to this package. Monitor npm accounts for unauthorized publishing activity. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10506
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a55ff8a68715ace432f47b6
Added to database: 07/14/2026, 09:21:14 UTC
Last enriched: 07/14/2026, 09:47:07 UTC
Last updated: 07/24/2026, 12:30:38 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.