Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in notify-theme (npm)

0
Critical
Published: 07/10/2026 (07/10/2026, 16:47:11 UTC)
Source: GCVE Database
Product: notify-theme

Description

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (d9cbb2ac45124e3844e29f3efd70ca26f0089ec4eaad718bcbdaf3035ec9b34b) The package impersonates the pino logger API (exports `module.exports.pino = middleware`, ships pino-style files such as lib/proto.js, lib/multistream.js, lib/transport.js, and declares logger-oriented keywords) while its actual behavior is a remote-code dropper. When a consumer imports and invokes the exported middleware, index.js spawns a detached Node child running lib/caller.js, which HTTP-GETs https://jsonkeeper.com/b/K80JD and passes the response body to `new Function.constructor('require', s)`, then invokes it with the host process's `require` — granting the remote endpoint arbitrary code execution inside the installer's Node process with full module access. lib/caller.js disguises the destination by shadowing `process` with a local object whose `env` fields (API_KEY, SECRET_KEY, SECRET_VALUE) actually hold the C2 URL and header pair. lib/const.js contains a base64-encoded backup endpoint that decodes to https://jsonkeeper.com/b/ZK45J. jsonkeeper.com is an anonymous, author-mutable paste host, so the executed payload can change at any time without a package update. The pino-API impersonation on an unrelated package name (`notify-theme`) is a lure so that developers looking for a logger trigger the dropper.

Affected software

npmghsa
notify-theme
Affected versions
=1.3.5=1.3.6=1.3.7

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/11/2026, 09:58:26 UTC

Technical Analysis

The 'notify-theme' npm package (versions 1.3.5 to 1.3.7) masquerades as the pino logger by exporting similarly named modules and files. However, its actual behavior is malicious: upon invocation, it spawns a detached Node.js child process that performs an HTTP GET request to a remote anonymous paste service (jsonkeeper.com) to retrieve JavaScript code. This code is then executed in the context of the host process using the Function constructor and the host's require function, granting the attacker arbitrary code execution capabilities with full module access. The package hides the command and control (C2) URL and headers inside environment-like variables within a local object to evade detection. The use of an anonymous, mutable paste host allows the attacker to change the payload at will without updating the package, increasing the threat's stealth and persistence.

Potential Impact

This vulnerability allows an attacker to execute arbitrary code remotely within the Node.js process that imports the malicious 'notify-theme' package. This can lead to full compromise of the host environment, including access to all modules and potentially sensitive data or system control. The dynamic nature of the payload, fetched from an anonymous mutable paste host, means the attacker can change the malicious code at any time, increasing the risk and making detection and mitigation more difficult.

Mitigation Recommendations

No official patch or remediation is currently documented for this malicious package. The best mitigation is to avoid using the 'notify-theme' package versions 1.3.5, 1.3.6, and 1.3.7 entirely. Developers should verify the authenticity of packages before installation, prefer well-known and trusted logging libraries, and audit dependencies for suspicious behavior. Since this is a malicious package impersonating a legitimate API, removing it from projects and replacing it with a verified logger package is recommended. Monitor for any unexpected child processes or network requests initiated by Node.js applications.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-10157
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a520ecc68715ace438f63ff

Added to database: 07/11/2026, 09:37:16 UTC

Last enriched: 07/11/2026, 09:58:26 UTC

Last updated: 07/25/2026, 18:28:58 UTC

Views: 21

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses