Malicious code in path-internal (npm)
The npm package 'path-internal' impersonates the Node.js core 'path' module but contains malicious code. It fetches and executes arbitrary code from an external URL via eval(), enabling remote code execution. The package uses obfuscation and typosquatting to disguise its malicious intent. Multiple versions of the package are affected.
AI Analysis
Technical Summary
The 'path-internal' npm package, which masquerades as a copy of the Node.js 'path' module, includes a malicious dropper inserted between standard path functions. Upon requiring the package, it decodes a base64-encoded URL pointing to a JSON document hosted on jsonkeeper.com, an anonymous mutable paste service. The package fetches this JSON and executes the 'content' field via eval(), allowing the attacker to run arbitrary code in the context of any process importing the package. A second similar payload is present but commented out. The use of obfuscation, misleading variable names, and typosquatting confirms deliberate malicious behavior. This was identified by Amazon Inspector and the OpenSSF Package Analysis project, which flagged the package for communicating with a malicious domain and executing commands associated with malicious activity.
Potential Impact
Any system that installs and requires the 'path-internal' package versions listed is at risk of remote code execution due to the package fetching and evaluating attacker-controlled code at runtime. This can lead to full compromise of the host environment where the package is used. The attacker can change the payload at any time, making the threat persistent and dynamic.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately remove and avoid installing the 'path-internal' package. Replace it with the official Node.js 'path' module or a trusted alternative. Monitor dependency trees for this package and block it in supply chain processes. Since the package fetches code from an external mutable source, network controls to block access to jsonkeeper.com may reduce risk. Check vendor advisories or npm security advisories for updates.
Malicious code in path-internal (npm)
Description
The npm package 'path-internal' impersonates the Node.js core 'path' module but contains malicious code. It fetches and executes arbitrary code from an external URL via eval(), enabling remote code execution. The package uses obfuscation and typosquatting to disguise its malicious intent. Multiple versions of the package are affected.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'path-internal' npm package, which masquerades as a copy of the Node.js 'path' module, includes a malicious dropper inserted between standard path functions. Upon requiring the package, it decodes a base64-encoded URL pointing to a JSON document hosted on jsonkeeper.com, an anonymous mutable paste service. The package fetches this JSON and executes the 'content' field via eval(), allowing the attacker to run arbitrary code in the context of any process importing the package. A second similar payload is present but commented out. The use of obfuscation, misleading variable names, and typosquatting confirms deliberate malicious behavior. This was identified by Amazon Inspector and the OpenSSF Package Analysis project, which flagged the package for communicating with a malicious domain and executing commands associated with malicious activity.
Potential Impact
Any system that installs and requires the 'path-internal' package versions listed is at risk of remote code execution due to the package fetching and evaluating attacker-controlled code at runtime. This can lead to full compromise of the host environment where the package is used. The attacker can change the payload at any time, making the threat persistent and dynamic.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately remove and avoid installing the 'path-internal' package. Replace it with the official Node.js 'path' module or a trusted alternative. Monitor dependency trees for this package and block it in supply chain processes. Since the package fetches code from an external mutable source, network controls to block access to jsonkeeper.com may reduce risk. Check vendor advisories or npm security advisories for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-2930
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-55cg-pqmh-hh6w"]
- Ecosystems
- ["npm"]
Threat ID: 6a96f318acd9273b49e49530
Added to database: 09/01/2026, 15:45:28 UTC
Last enriched: 09/08/2026, 12:54:28 UTC
Last updated: 09/08/2026, 12:54:28 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.