Malicious code in nottuff7 (npm)
The npm package 'nottuff7' version 1.7.7 is part of a coordinated spam-publication family republishing a Scramjet web-proxy payload as a static site. Its main entry is a browser ServiceWorker script that does not execute code during installation or runtime in Node.js, thus no install-time code execution or credential theft occurs. The malicious behavior manifests when the package assets are served to browsers via npm CDN services, enabling proxy usage that bypasses web filters and serves ad-monetization content. Although no direct installer-side exploitation is present, any system with this package installed should be considered compromised due to the potential for full control via the browser context. Immediate removal and secret/key rotation are recommended.
AI Analysis
Technical Summary
The 'nottuff7' npm package version 1.7.7 is identified as malicious, belonging to a family of packages that republish the same Scramjet web-proxy payload. The package's main entry point is a ServiceWorker script intended to run in browsers, not Node.js, preventing install-time code execution or lifecycle hook exploitation. The malicious payload is heavily obfuscated and delivered through assets served by npm CDN hosts, allowing users to bypass web filters by accessing the proxy via registry-CDN hostnames. The package also includes a popunder ad-monetization mechanism. Despite no installer-side credential theft or remote code execution, the presence of this package indicates a fully compromised environment, as stated by the GHSA-malware source.
Potential Impact
Systems with 'nottuff7' version 1.7.7 installed may be fully compromised, as the package enables a web-proxy payload that can be used to bypass web filters and deliver malicious or unwanted content. While no installer-side code execution or credential theft occurs, the browser-executed ServiceWorker can facilitate unauthorized proxying and ad-monetization. The compromise risk extends to all secrets and keys on the affected system, which should be considered exposed.
Mitigation Recommendations
There is no official patch or fix available for this malicious package. The recommended mitigation is immediate removal of the 'nottuff7' package version 1.7.7 from all affected systems. Additionally, all secrets and keys stored on compromised systems should be rotated immediately from a secure, unaffected environment. Monitor for any signs of persistent compromise beyond the presence of this package.
Malicious code in nottuff7 (npm)
Description
The npm package 'nottuff7' version 1.7.7 is part of a coordinated spam-publication family republishing a Scramjet web-proxy payload as a static site. Its main entry is a browser ServiceWorker script that does not execute code during installation or runtime in Node.js, thus no install-time code execution or credential theft occurs. The malicious behavior manifests when the package assets are served to browsers via npm CDN services, enabling proxy usage that bypasses web filters and serves ad-monetization content. Although no direct installer-side exploitation is present, any system with this package installed should be considered compromised due to the potential for full control via the browser context. Immediate removal and secret/key rotation are recommended.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'nottuff7' npm package version 1.7.7 is identified as malicious, belonging to a family of packages that republish the same Scramjet web-proxy payload. The package's main entry point is a ServiceWorker script intended to run in browsers, not Node.js, preventing install-time code execution or lifecycle hook exploitation. The malicious payload is heavily obfuscated and delivered through assets served by npm CDN hosts, allowing users to bypass web filters by accessing the proxy via registry-CDN hostnames. The package also includes a popunder ad-monetization mechanism. Despite no installer-side credential theft or remote code execution, the presence of this package indicates a fully compromised environment, as stated by the GHSA-malware source.
Potential Impact
Systems with 'nottuff7' version 1.7.7 installed may be fully compromised, as the package enables a web-proxy payload that can be used to bypass web filters and deliver malicious or unwanted content. While no installer-side code execution or credential theft occurs, the browser-executed ServiceWorker can facilitate unauthorized proxying and ad-monetization. The compromise risk extends to all secrets and keys on the affected system, which should be considered exposed.
Mitigation Recommendations
There is no official patch or fix available for this malicious package. The recommended mitigation is immediate removal of the 'nottuff7' package version 1.7.7 from all affected systems. Additionally, all secrets and keys stored on compromised systems should be rotated immediately from a secure, unaffected environment. Monitor for any signs of persistent compromise beyond the presence of this package.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-5918
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-f4m6-gffx-m3mq"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a54ad9668715ace438f05c5
Added to database: 07/13/2026, 09:19:18 UTC
Last enriched: 07/13/2026, 09:23:59 UTC
Last updated: 07/22/2026, 07:10:04 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.