Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in node-fsmetrics-native (npm)

0
Critical
Published: 07/13/2026 (07/13/2026, 19:44:27 UTC)
Source: GCVE Database
Product: node-fsmetrics-native

Description

The node-fsmetrics-native npm package version 1.0.0 contains malicious code that establishes a backdoor to a remote command and control (C2) server. Upon requiring the package, it decodes a URL and continuously polls the server for commands, executing them via bash and sending back the results. Additionally, a native addon component launches a separate thread that redundantly fetches and executes commands from the same server using curl and python3. The C2 server address is obfuscated in both JavaScript and native code to evade detection.

Affected software

npmghsa
node-fsmetrics-native
Affected versions
=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/14/2026, 09:53:45 UTC

Technical Analysis

The node-fsmetrics-native package version 1.0.0 includes embedded malicious functionality. The JavaScript entry point decodes a hex-encoded URL pointing to a remote server and starts a background loop that polls for commands, executes them with bash, and posts execution results back to the server. Concurrently, a native addon (sysmon.cc) invoked via GetCpuInfo XOR-decodes the same server address and launches a detached pthread that runs a curl and python3 loop to fetch and execute commands, providing a redundant backdoor channel. Both the JavaScript and native code obfuscate the C2 server address to avoid straightforward detection.

Potential Impact

This malicious package enables remote attackers controlling the C2 server to execute arbitrary commands on any system that installs and runs node-fsmetrics-native version 1.0.0. The attacker gains full remote code execution capabilities, including the ability to run shell commands and scripts, potentially leading to system compromise, data theft, or further malware deployment.

Mitigation Recommendations

No official patch or remediation is currently available for this malicious package version. Users should immediately remove node-fsmetrics-native version 1.0.0 from their environments and avoid installing it. Verify dependencies to ensure this package is not included transitively. Monitor for any unexpected network connections to the indicated IP address (152.53.120.90) and consider incident response if this package was deployed. Check vendor advisories or trusted sources for updates regarding remediation or replacement packages.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-10480
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a55ffa268715ace432f733f

Added to database: 07/14/2026, 09:21:38 UTC

Last enriched: 07/14/2026, 09:53:45 UTC

Last updated: 07/26/2026, 12:01:04 UTC

Views: 16

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses