Malicious code in node-sysmon-native (npm)
The node-sysmon-native npm package versions 1.0.0, 1.0.1, and 1.0.2 contain malicious code that, upon module load, reconstructs a hex-encoded URL pointing to a remote IP address. The package enters an asynchronous loop polling this remote host for shell commands, executes them on the local system with bash, and exfiltrates the output back to the attacker. This behavior grants arbitrary shell execution and data exfiltration capabilities to the operator of the remote server. The package's declared purpose does not justify this network activity, indicating malicious intent.
AI Analysis
Technical Summary
The node-sysmon-native package (versions 1.0.0, 1.0.1, and 1.0.2) includes embedded malicious code that reconstructs a hex-encoded URL (http://152.53.120.90/cmd) at runtime to evade static detection. It continuously polls this URL for commands, executes them synchronously using bash with a timeout and output buffer, and sends the command results back to the attacker-controlled server. Any application that imports this package effectively grants remote arbitrary shell command execution with output exfiltration, posing a severe security risk.
Potential Impact
This malicious package enables an attacker to execute arbitrary shell commands on the affected host and exfiltrate command outputs, leading to potential full system compromise, data leakage, and unauthorized control. The use of a hardcoded IP address and obfuscated URL reconstruction complicates detection by static analysis tools.
Mitigation Recommendations
Users should immediately remove and replace the node-sysmon-native package versions 1.0.0, 1.0.1, and 1.0.2 from their projects. Since no patch or official fix is available, avoid using this package entirely. Conduct audits of systems where this package was installed to detect any signs of compromise or unauthorized command execution.
Malicious code in node-sysmon-native (npm)
Description
The node-sysmon-native npm package versions 1.0.0, 1.0.1, and 1.0.2 contain malicious code that, upon module load, reconstructs a hex-encoded URL pointing to a remote IP address. The package enters an asynchronous loop polling this remote host for shell commands, executes them on the local system with bash, and exfiltrates the output back to the attacker. This behavior grants arbitrary shell execution and data exfiltration capabilities to the operator of the remote server. The package's declared purpose does not justify this network activity, indicating malicious intent.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The node-sysmon-native package (versions 1.0.0, 1.0.1, and 1.0.2) includes embedded malicious code that reconstructs a hex-encoded URL (http://152.53.120.90/cmd) at runtime to evade static detection. It continuously polls this URL for commands, executes them synchronously using bash with a timeout and output buffer, and sends the command results back to the attacker-controlled server. Any application that imports this package effectively grants remote arbitrary shell command execution with output exfiltration, posing a severe security risk.
Potential Impact
This malicious package enables an attacker to execute arbitrary shell commands on the affected host and exfiltrate command outputs, leading to potential full system compromise, data leakage, and unauthorized control. The use of a hardcoded IP address and obfuscated URL reconstruction complicates detection by static analysis tools.
Mitigation Recommendations
Users should immediately remove and replace the node-sysmon-native package versions 1.0.0, 1.0.1, and 1.0.2 from their projects. Since no patch or official fix is available, avoid using this package entirely. Conduct audits of systems where this package was installed to detect any signs of compromise or unauthorized command execution.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10465
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a55ffb368715ace432fa9b6
Added to database: 07/14/2026, 09:21:55 UTC
Last enriched: 07/14/2026, 09:57:46 UTC
Last updated: 07/31/2026, 15:47:11 UTC
Views: 42
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.