Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in nottuff25 (npm)

0
High
Published: 06/16/2026 (06/16/2026, 19:27:25 UTC)
Source: GCVE Database
Product: nottuff25

Description

The npm package 'nottuff25' version 1.7.7 is identified as malicious. It misrepresents itself by shipping a browser ServiceWorker and a static site unrelated to its advertised purpose. The package contains a bash script that automates mass publication of numerous sibling malicious packages, indicating a coordinated namespace-pollution campaign. Additionally, it includes browser-side adware that opens a popunder on user interaction. There is no evidence of install-time remote code execution or credential theft, but the package's presence indicates a compromised environment.

Affected software

npmghsa
nottuff25
Affected versions
=1.7.7

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/13/2026, 09:24:20 UTC

Technical Analysis

The 'nottuff25' npm package (version 1.7.7) is a malicious artifact that does not function as a legitimate Node library. Instead, it includes a browser ServiceWorker script and a static site bundling unrelated web proxies and branding, misleading npm consumers. It contains an embedded bash script designed to mass-publish a large set of similarly named malicious packages, including itself, demonstrating an automated attack infrastructure. The package also implements browser-based adware behavior by opening a popunder on first user interaction. Although it does not perform install-time exfiltration, remote code execution, or credential theft, its installation compromises the integrity of the host environment and pollutes the npm namespace.

Potential Impact

Installation of this package compromises the host environment by introducing malicious scripts and adware. The embedded mass-publication script facilitates widespread distribution of additional malicious packages, increasing the attack surface. While no direct remote code execution or credential theft occurs at install or require time, the presence of this package signals a fully compromised system per one source, necessitating immediate security measures. The browser adware component affects user experience by opening unwanted popunder windows.

Mitigation Recommendations

Remove the 'nottuff25' package version 1.7.7 immediately from all systems. Rotate all secrets and keys stored on affected computers from a secure, uncompromised environment. Since the package is part of a coordinated namespace-pollution campaign and may indicate full system compromise, conduct a thorough security assessment and remediation of the affected systems. No official patch or fix is available; remediation requires removal and system recovery actions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-5916
Osv Schema Version
1.7.4
Aliases
["GHSA-2gj2-9868-32pf"]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a54ad9668715ace438f05cd

Added to database: 07/13/2026, 09:19:18 UTC

Last enriched: 07/13/2026, 09:24:20 UTC

Last updated: 07/30/2026, 21:47:31 UTC

Views: 13

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses