Malicious code in nodemon-delog (npm)
The nodemon-delog npm package impersonates the legitimate nodemon package by copying its source code, metadata, and author information. It declares two runtime dependencies, type-atob and chai, which are not used or referenced by its code but are installed when nodemon-delog is installed. This behavior forces these dependencies into the installer's dependency tree, potentially executing their install or require-time code. The package itself contains no direct exfiltration or remote code execution code, but the dependency-smuggling pattern poses a supply chain risk.
AI Analysis
Technical Summary
nodemon-delog is a malicious npm package that mimics the widely-used nodemon package by replicating its source tree, README, homepage, author, and repository metadata. Unlike nodemon, nodemon-delog declares two runtime dependencies, type-atob and chai, which are not imported or used by its code. These dependencies are installed automatically when nodemon-delog is installed, potentially executing code during installation or require-time. This technique, known as dependency-smuggling, leverages impersonation to introduce unwanted packages into a consumer's dependency tree, posing a supply chain threat. There is no direct evidence of exfiltration or remote code execution within nodemon-delog itself.
Potential Impact
The primary impact is the forced installation and potential execution of code from the type-atob and chai packages due to nodemon-delog's dependency declarations. While nodemon-delog does not contain direct malicious payloads, the inclusion of these dependencies without reference in the code can lead to unexpected code execution during installation or runtime, increasing supply chain risk. There are no known exploits in the wild for this package as of the published date.
Mitigation Recommendations
No official patch or fix is currently available for nodemon-delog. Users should avoid installing nodemon-delog, especially version 3.1.13, and verify package authenticity before installation. Rely on the legitimate nodemon package from trusted sources. Monitor dependency trees for suspicious or unexpected packages. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for current remediation guidance.
Malicious code in nodemon-delog (npm)
Description
The nodemon-delog npm package impersonates the legitimate nodemon package by copying its source code, metadata, and author information. It declares two runtime dependencies, type-atob and chai, which are not used or referenced by its code but are installed when nodemon-delog is installed. This behavior forces these dependencies into the installer's dependency tree, potentially executing their install or require-time code. The package itself contains no direct exfiltration or remote code execution code, but the dependency-smuggling pattern poses a supply chain risk.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
nodemon-delog is a malicious npm package that mimics the widely-used nodemon package by replicating its source tree, README, homepage, author, and repository metadata. Unlike nodemon, nodemon-delog declares two runtime dependencies, type-atob and chai, which are not imported or used by its code. These dependencies are installed automatically when nodemon-delog is installed, potentially executing code during installation or require-time. This technique, known as dependency-smuggling, leverages impersonation to introduce unwanted packages into a consumer's dependency tree, posing a supply chain threat. There is no direct evidence of exfiltration or remote code execution within nodemon-delog itself.
Potential Impact
The primary impact is the forced installation and potential execution of code from the type-atob and chai packages due to nodemon-delog's dependency declarations. While nodemon-delog does not contain direct malicious payloads, the inclusion of these dependencies without reference in the code can lead to unexpected code execution during installation or runtime, increasing supply chain risk. There are no known exploits in the wild for this package as of the published date.
Mitigation Recommendations
No official patch or fix is currently available for nodemon-delog. Users should avoid installing nodemon-delog, especially version 3.1.13, and verify package authenticity before installation. Rely on the legitimate nodemon package from trusted sources. Monitor dependency trees for suspicious or unexpected packages. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10507
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a55ff8e68715ace432f4a6f
Added to database: 07/14/2026, 09:21:18 UTC
Last enriched: 07/14/2026, 09:47:34 UTC
Last updated: 07/31/2026, 14:36:42 UTC
Views: 23
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.