Malicious code in nottuff25 (npm)
The npm package 'nottuff25' version 1.7.7 is identified as malicious. It misrepresents itself by shipping a browser ServiceWorker and a static site unrelated to its advertised purpose. The package contains a bash script that automates mass publication of numerous sibling malicious packages, indicating a coordinated namespace-pollution campaign. Additionally, it includes browser-side adware that opens a popunder on user interaction. There is no evidence of install-time remote code execution or credential theft, but the package's presence indicates a compromised environment.
AI Analysis
Technical Summary
The 'nottuff25' npm package (version 1.7.7) is a malicious artifact that does not function as a legitimate Node library. Instead, it includes a browser ServiceWorker script and a static site bundling unrelated web proxies and branding, misleading npm consumers. It contains an embedded bash script designed to mass-publish a large set of similarly named malicious packages, including itself, demonstrating an automated attack infrastructure. The package also implements browser-based adware behavior by opening a popunder on first user interaction. Although it does not perform install-time exfiltration, remote code execution, or credential theft, its installation compromises the integrity of the host environment and pollutes the npm namespace.
Potential Impact
Installation of this package compromises the host environment by introducing malicious scripts and adware. The embedded mass-publication script facilitates widespread distribution of additional malicious packages, increasing the attack surface. While no direct remote code execution or credential theft occurs at install or require time, the presence of this package signals a fully compromised system per one source, necessitating immediate security measures. The browser adware component affects user experience by opening unwanted popunder windows.
Mitigation Recommendations
Remove the 'nottuff25' package version 1.7.7 immediately from all systems. Rotate all secrets and keys stored on affected computers from a secure, uncompromised environment. Since the package is part of a coordinated namespace-pollution campaign and may indicate full system compromise, conduct a thorough security assessment and remediation of the affected systems. No official patch or fix is available; remediation requires removal and system recovery actions.
Malicious code in nottuff25 (npm)
Description
The npm package 'nottuff25' version 1.7.7 is identified as malicious. It misrepresents itself by shipping a browser ServiceWorker and a static site unrelated to its advertised purpose. The package contains a bash script that automates mass publication of numerous sibling malicious packages, indicating a coordinated namespace-pollution campaign. Additionally, it includes browser-side adware that opens a popunder on user interaction. There is no evidence of install-time remote code execution or credential theft, but the package's presence indicates a compromised environment.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'nottuff25' npm package (version 1.7.7) is a malicious artifact that does not function as a legitimate Node library. Instead, it includes a browser ServiceWorker script and a static site bundling unrelated web proxies and branding, misleading npm consumers. It contains an embedded bash script designed to mass-publish a large set of similarly named malicious packages, including itself, demonstrating an automated attack infrastructure. The package also implements browser-based adware behavior by opening a popunder on first user interaction. Although it does not perform install-time exfiltration, remote code execution, or credential theft, its installation compromises the integrity of the host environment and pollutes the npm namespace.
Potential Impact
Installation of this package compromises the host environment by introducing malicious scripts and adware. The embedded mass-publication script facilitates widespread distribution of additional malicious packages, increasing the attack surface. While no direct remote code execution or credential theft occurs at install or require time, the presence of this package signals a fully compromised system per one source, necessitating immediate security measures. The browser adware component affects user experience by opening unwanted popunder windows.
Mitigation Recommendations
Remove the 'nottuff25' package version 1.7.7 immediately from all systems. Rotate all secrets and keys stored on affected computers from a secure, uncompromised environment. Since the package is part of a coordinated namespace-pollution campaign and may indicate full system compromise, conduct a thorough security assessment and remediation of the affected systems. No official patch or fix is available; remediation requires removal and system recovery actions.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-5916
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-2gj2-9868-32pf"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a54ad9668715ace438f05cd
Added to database: 07/13/2026, 09:19:18 UTC
Last enriched: 07/13/2026, 09:24:20 UTC
Last updated: 07/30/2026, 21:47:31 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.