Skip to main content

Malicious code in path-internal (npm)

0
Critical
Published: 04/14/2026 (04/14/2026, 10:53:25 UTC)
Source: GCVE Database
Product: path-internal

Description

The npm package 'path-internal' impersonates the Node.js core 'path' module but contains malicious code. It fetches and executes arbitrary code from an external URL via eval(), enabling remote code execution. The package uses obfuscation and typosquatting to disguise its malicious intent. Multiple versions of the package are affected.

Affected software

npmghsa
path-internal
Affected versions
=1.0.10=1.0.11=1.0.12=1.0.14=1.0.13=1.0.15=1.0.0=1.0.1=1.0.2=1.0.3=1.0.4=1.0.5=1.0.6=1.0.7=1.0.8=1.0.9

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/08/2026, 12:54:28 UTC

Technical Analysis

The 'path-internal' npm package, which masquerades as a copy of the Node.js 'path' module, includes a malicious dropper inserted between standard path functions. Upon requiring the package, it decodes a base64-encoded URL pointing to a JSON document hosted on jsonkeeper.com, an anonymous mutable paste service. The package fetches this JSON and executes the 'content' field via eval(), allowing the attacker to run arbitrary code in the context of any process importing the package. A second similar payload is present but commented out. The use of obfuscation, misleading variable names, and typosquatting confirms deliberate malicious behavior. This was identified by Amazon Inspector and the OpenSSF Package Analysis project, which flagged the package for communicating with a malicious domain and executing commands associated with malicious activity.

Potential Impact

Any system that installs and requires the 'path-internal' package versions listed is at risk of remote code execution due to the package fetching and evaluating attacker-controlled code at runtime. This can lead to full compromise of the host environment where the package is used. The attacker can change the payload at any time, making the threat persistent and dynamic.

Mitigation Recommendations

No official patch or remediation is currently documented. Users should immediately remove and avoid installing the 'path-internal' package. Replace it with the official Node.js 'path' module or a trusted alternative. Monitor dependency trees for this package and block it in supply chain processes. Since the package fetches code from an external mutable source, network controls to block access to jsonkeeper.com may reduce risk. Check vendor advisories or npm security advisories for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-2930
Osv Schema Version
1.7.4
Aliases
["GHSA-55cg-pqmh-hh6w"]
Ecosystems
["npm"]

Threat ID: 6a96f318acd9273b49e49530

Added to database: 09/01/2026, 15:45:28 UTC

Last enriched: 09/08/2026, 12:54:28 UTC

Last updated: 09/08/2026, 12:54:28 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses