Malicious code in nolimit-agent (npm)
The npm package 'nolimit-agent' is a malicious toolkit designed for mass-mail and SMS spam campaigns, including phishing. It uses heavy JavaScript obfuscation to evade detection and includes features such as bulk SMTP sending, SMS via carrier email gateways, and contact harvesting via OAuth flows against Microsoft and Google APIs. The package collects OAuth tokens locally and uses them to enumerate contacts for spam targeting. It also performs license verification over unencrypted HTTP. Installing or running this package compromises the host machine, turning it into a platform for outbound abuse. Removal of the package does not guarantee full remediation due to potential persistent compromise.
AI Analysis
Technical Summary
The 'nolimit-agent' npm package is a weaponized spam and phishing toolkit distributed with obfuscated JavaScript code to evade detection. It supports bulk SMTP and SMS sending, scanner evasion techniques including obfuscated HTML attachments and SVG-based payload delivery, and DKIM key generation. The package implements OAuth device-code flows against Microsoft and Google to harvest contacts from Microsoft Graph and Google People APIs, storing tokens locally without relaying them to the attacker. It performs license checks via unencrypted HTTP requests. The Windows postinstall script is benign and does not perform network activity. The package does not exfiltrate installer secrets on installation but enables the installer's machine and accounts to be abused for outbound spam and phishing. The obfuscation is designed to defeat registry scanning. Any system with this package installed or running should be considered fully compromised.
Potential Impact
Systems with 'nolimit-agent' installed or running are fully compromised, as the package enables mass spam and phishing campaigns using the victim's machine and accounts. OAuth tokens harvested locally can be used to access contacts and prior recipients for further abuse. The package's obfuscation and evasion techniques hinder detection and removal. Secrets and keys stored on the compromised system should be rotated immediately from a clean environment. Removal of the package alone may not eliminate all malicious components or control established by the attacker.
Mitigation Recommendations
No official patch or fix is available. The package should be removed immediately. Due to the high likelihood of full system compromise, all secrets and keys stored on the affected machine must be rotated from a separate, trusted device. Incident response should assume complete compromise of the host. Monitor for any signs of persistent malicious activity and consider rebuilding the affected system from a known good state.
Malicious code in nolimit-agent (npm)
Description
The npm package 'nolimit-agent' is a malicious toolkit designed for mass-mail and SMS spam campaigns, including phishing. It uses heavy JavaScript obfuscation to evade detection and includes features such as bulk SMTP sending, SMS via carrier email gateways, and contact harvesting via OAuth flows against Microsoft and Google APIs. The package collects OAuth tokens locally and uses them to enumerate contacts for spam targeting. It also performs license verification over unencrypted HTTP. Installing or running this package compromises the host machine, turning it into a platform for outbound abuse. Removal of the package does not guarantee full remediation due to potential persistent compromise.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'nolimit-agent' npm package is a weaponized spam and phishing toolkit distributed with obfuscated JavaScript code to evade detection. It supports bulk SMTP and SMS sending, scanner evasion techniques including obfuscated HTML attachments and SVG-based payload delivery, and DKIM key generation. The package implements OAuth device-code flows against Microsoft and Google to harvest contacts from Microsoft Graph and Google People APIs, storing tokens locally without relaying them to the attacker. It performs license checks via unencrypted HTTP requests. The Windows postinstall script is benign and does not perform network activity. The package does not exfiltrate installer secrets on installation but enables the installer's machine and accounts to be abused for outbound spam and phishing. The obfuscation is designed to defeat registry scanning. Any system with this package installed or running should be considered fully compromised.
Potential Impact
Systems with 'nolimit-agent' installed or running are fully compromised, as the package enables mass spam and phishing campaigns using the victim's machine and accounts. OAuth tokens harvested locally can be used to access contacts and prior recipients for further abuse. The package's obfuscation and evasion techniques hinder detection and removal. Secrets and keys stored on the compromised system should be rotated immediately from a clean environment. Removal of the package alone may not eliminate all malicious components or control established by the attacker.
Mitigation Recommendations
No official patch or fix is available. The package should be removed immediately. Due to the high likelihood of full system compromise, all secrets and keys stored on the affected machine must be rotated from a separate, trusted device. Incident response should assume complete compromise of the host. Monitor for any signs of persistent malicious activity and consider rebuilding the affected system from a known good state.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12183
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-f9mj-p83x-395v"]
- Ecosystems
- ["npm"]
Threat ID: 6a7f43f1bf8831d5395d763e
Added to database: 08/14/2026, 16:36:01 UTC
Last enriched: 08/14/2026, 16:47:08 UTC
Last updated: 09/26/2026, 00:05:38 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.