Skip to main content

Malicious code in nolimit-agent (npm)

0
Critical
Published: 08/05/2026 (08/05/2026, 08:50:21 UTC)
Source: GCVE Database
Product: nolimit-agent

Description

The npm package 'nolimit-agent' is a malicious toolkit designed for mass-mail and SMS spam campaigns, including phishing. It uses heavy JavaScript obfuscation to evade detection and includes features such as bulk SMTP sending, SMS via carrier email gateways, and contact harvesting via OAuth flows against Microsoft and Google APIs. The package collects OAuth tokens locally and uses them to enumerate contacts for spam targeting. It also performs license verification over unencrypted HTTP. Installing or running this package compromises the host machine, turning it into a platform for outbound abuse. Removal of the package does not guarantee full remediation due to potential persistent compromise.

Affected software

npmghsa
nolimit-agent
Affected versions
=1.0.343=1.0.309=1.0.313=1.0.318=1.0.330=1.0.300=1.0.339=1.0.332=1.0.307=1.0.311=1.0.306=1.0.325=1.0.340=1.0.324=1.0.301=1.0.326=1.0.315=1.0.308=1.0.316=1.0.314=1.0.323=1.0.346=1.0.328=1.0.341=1.0.334=1.0.338=1.0.331=1.0.317=1.0.337=1.0.312=1.0.329=1.0.299=1.0.344=1.0.310=1.0.303=1.0.327=1.0.320=1.0.321=1.0.333=1.0.322=1.0.336=1.0.305=1.0.319=1.0.342=1.0.302=1.0.335=1.0.345

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 16:47:08 UTC

Technical Analysis

The 'nolimit-agent' npm package is a weaponized spam and phishing toolkit distributed with obfuscated JavaScript code to evade detection. It supports bulk SMTP and SMS sending, scanner evasion techniques including obfuscated HTML attachments and SVG-based payload delivery, and DKIM key generation. The package implements OAuth device-code flows against Microsoft and Google to harvest contacts from Microsoft Graph and Google People APIs, storing tokens locally without relaying them to the attacker. It performs license checks via unencrypted HTTP requests. The Windows postinstall script is benign and does not perform network activity. The package does not exfiltrate installer secrets on installation but enables the installer's machine and accounts to be abused for outbound spam and phishing. The obfuscation is designed to defeat registry scanning. Any system with this package installed or running should be considered fully compromised.

Potential Impact

Systems with 'nolimit-agent' installed or running are fully compromised, as the package enables mass spam and phishing campaigns using the victim's machine and accounts. OAuth tokens harvested locally can be used to access contacts and prior recipients for further abuse. The package's obfuscation and evasion techniques hinder detection and removal. Secrets and keys stored on the compromised system should be rotated immediately from a clean environment. Removal of the package alone may not eliminate all malicious components or control established by the attacker.

Mitigation Recommendations

No official patch or fix is available. The package should be removed immediately. Due to the high likelihood of full system compromise, all secrets and keys stored on the affected machine must be rotated from a separate, trusted device. Incident response should assume complete compromise of the host. Monitor for any signs of persistent malicious activity and consider rebuilding the affected system from a known good state.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-12183
Osv Schema Version
1.7.4
Aliases
["GHSA-f9mj-p83x-395v"]
Ecosystems
["npm"]

Threat ID: 6a7f43f1bf8831d5395d763e

Added to database: 08/14/2026, 16:36:01 UTC

Last enriched: 08/14/2026, 16:47:08 UTC

Last updated: 09/26/2026, 00:05:38 UTC

Views: 18

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses