Malicious code in node-fsmetrics-native (npm)
The node-fsmetrics-native npm package version 1.0.0 contains malicious code that establishes a backdoor to a remote command and control (C2) server. Upon requiring the package, it decodes a URL and continuously polls the server for commands, executing them via bash and sending back the results. Additionally, a native addon component launches a separate thread that redundantly fetches and executes commands from the same server using curl and python3. The C2 server address is obfuscated in both JavaScript and native code to evade detection.
AI Analysis
Technical Summary
The node-fsmetrics-native package version 1.0.0 includes embedded malicious functionality. The JavaScript entry point decodes a hex-encoded URL pointing to a remote server and starts a background loop that polls for commands, executes them with bash, and posts execution results back to the server. Concurrently, a native addon (sysmon.cc) invoked via GetCpuInfo XOR-decodes the same server address and launches a detached pthread that runs a curl and python3 loop to fetch and execute commands, providing a redundant backdoor channel. Both the JavaScript and native code obfuscate the C2 server address to avoid straightforward detection.
Potential Impact
This malicious package enables remote attackers controlling the C2 server to execute arbitrary commands on any system that installs and runs node-fsmetrics-native version 1.0.0. The attacker gains full remote code execution capabilities, including the ability to run shell commands and scripts, potentially leading to system compromise, data theft, or further malware deployment.
Mitigation Recommendations
No official patch or remediation is currently available for this malicious package version. Users should immediately remove node-fsmetrics-native version 1.0.0 from their environments and avoid installing it. Verify dependencies to ensure this package is not included transitively. Monitor for any unexpected network connections to the indicated IP address (152.53.120.90) and consider incident response if this package was deployed. Check vendor advisories or trusted sources for updates regarding remediation or replacement packages.
Malicious code in node-fsmetrics-native (npm)
Description
The node-fsmetrics-native npm package version 1.0.0 contains malicious code that establishes a backdoor to a remote command and control (C2) server. Upon requiring the package, it decodes a URL and continuously polls the server for commands, executing them via bash and sending back the results. Additionally, a native addon component launches a separate thread that redundantly fetches and executes commands from the same server using curl and python3. The C2 server address is obfuscated in both JavaScript and native code to evade detection.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The node-fsmetrics-native package version 1.0.0 includes embedded malicious functionality. The JavaScript entry point decodes a hex-encoded URL pointing to a remote server and starts a background loop that polls for commands, executes them with bash, and posts execution results back to the server. Concurrently, a native addon (sysmon.cc) invoked via GetCpuInfo XOR-decodes the same server address and launches a detached pthread that runs a curl and python3 loop to fetch and execute commands, providing a redundant backdoor channel. Both the JavaScript and native code obfuscate the C2 server address to avoid straightforward detection.
Potential Impact
This malicious package enables remote attackers controlling the C2 server to execute arbitrary commands on any system that installs and runs node-fsmetrics-native version 1.0.0. The attacker gains full remote code execution capabilities, including the ability to run shell commands and scripts, potentially leading to system compromise, data theft, or further malware deployment.
Mitigation Recommendations
No official patch or remediation is currently available for this malicious package version. Users should immediately remove node-fsmetrics-native version 1.0.0 from their environments and avoid installing it. Verify dependencies to ensure this package is not included transitively. Monitor for any unexpected network connections to the indicated IP address (152.53.120.90) and consider incident response if this package was deployed. Check vendor advisories or trusted sources for updates regarding remediation or replacement packages.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10480
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a55ffa268715ace432f733f
Added to database: 07/14/2026, 09:21:38 UTC
Last enriched: 07/14/2026, 09:53:45 UTC
Last updated: 07/26/2026, 12:01:04 UTC
Views: 16
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.