Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in nottuff7 (npm)

0
High
Published: 06/16/2026 (06/16/2026, 19:27:27 UTC)
Source: GCVE Database
Product: nottuff7

Description

The npm package 'nottuff7' version 1.7.7 is part of a coordinated spam-publication family republishing a Scramjet web-proxy payload as a static site. Its main entry is a browser ServiceWorker script that does not execute code during installation or runtime in Node.js, thus no install-time code execution or credential theft occurs. The malicious behavior manifests when the package assets are served to browsers via npm CDN services, enabling proxy usage that bypasses web filters and serves ad-monetization content. Although no direct installer-side exploitation is present, any system with this package installed should be considered compromised due to the potential for full control via the browser context. Immediate removal and secret/key rotation are recommended.

Affected software

npmghsa
nottuff7
Affected versions
=1.7.7

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/13/2026, 09:23:59 UTC

Technical Analysis

The 'nottuff7' npm package version 1.7.7 is identified as malicious, belonging to a family of packages that republish the same Scramjet web-proxy payload. The package's main entry point is a ServiceWorker script intended to run in browsers, not Node.js, preventing install-time code execution or lifecycle hook exploitation. The malicious payload is heavily obfuscated and delivered through assets served by npm CDN hosts, allowing users to bypass web filters by accessing the proxy via registry-CDN hostnames. The package also includes a popunder ad-monetization mechanism. Despite no installer-side credential theft or remote code execution, the presence of this package indicates a fully compromised environment, as stated by the GHSA-malware source.

Potential Impact

Systems with 'nottuff7' version 1.7.7 installed may be fully compromised, as the package enables a web-proxy payload that can be used to bypass web filters and deliver malicious or unwanted content. While no installer-side code execution or credential theft occurs, the browser-executed ServiceWorker can facilitate unauthorized proxying and ad-monetization. The compromise risk extends to all secrets and keys on the affected system, which should be considered exposed.

Mitigation Recommendations

There is no official patch or fix available for this malicious package. The recommended mitigation is immediate removal of the 'nottuff7' package version 1.7.7 from all affected systems. Additionally, all secrets and keys stored on compromised systems should be rotated immediately from a secure, unaffected environment. Monitor for any signs of persistent compromise beyond the presence of this package.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-5918
Osv Schema Version
1.7.4
Aliases
["GHSA-f4m6-gffx-m3mq"]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a54ad9668715ace438f05c5

Added to database: 07/13/2026, 09:19:18 UTC

Last enriched: 07/13/2026, 09:23:59 UTC

Last updated: 07/22/2026, 07:10:04 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses