Malicious code in paysafe-fraud (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (a596646a3604e01bef558573fc7199a2b9e9cc07ab7edae1b7e445d2e2b860b6) Package advertises itself as the 'Paysafe Fraud Prevention SDK' (name paysafe-fraud, repo github.com/paysafe/paysafe-fraud) but the exported PaysafeClient (payments.create/get, customers.create/get) schedules a hidden __exfil() call via setTimeout on every API invocation. __exfil enumerates process.env, filters variables whose names contain XOR-decoded substrings for 'key', 'secret', 'token', 'password', 'auth', and 'api', truncates each value to 100 chars, and combines them with os.hostname(), os.userInfo().username, process.cwd(), a timestamp, the package name, and the first 10 characters of the caller-supplied apiKey. The resulting JSON is POSTed over TCP 8443 to an XOR-obfuscated hardcoded hostname with an XOR-obfuscated path. All sensitive strings (destination host, HTTP method/headers, env-key filters) are decoded at runtime via an __x() XOR routine keyed by a hardcoded base64 blob. A __check() guard aborts exfil when os.cpus().length < 2 or when the hostname/username matches a decoded analyst/sandbox blocklist, indicating deliberate anti-analysis. This is a brand-impersonation typosquat carrying a credential-stealer payload; the harm fires as soon as a consumer application uses the SDK's documented API, delivering caller credentials and host identifiers to attacker infrastructure.
AI Analysis
Technical Summary
The 'paysafe-fraud' npm package (version 1.0.0) masquerades as the Paysafe Fraud Prevention SDK but contains a hidden exfiltration function (__exfil) that activates on every API invocation. This function collects environment variables filtered for sensitive keys (e.g., 'key', 'secret', 'token', 'password', 'auth', 'api'), truncates their values, and combines them with host identifiers such as hostname, username, current working directory, a timestamp, the package name, and part of the caller's API key. The collected data is sent via HTTPS POST to an attacker-controlled server with obfuscated hostname and path, decoded at runtime. The package includes anti-analysis logic that aborts exfiltration if the environment appears to be a sandbox or analyst machine (e.g., CPU count less than 2 or blacklisted hostnames/usernames). This is a credential-stealing payload delivered through a brand-impersonation typosquat.
Potential Impact
Use of this package results in the compromise of environment credentials and host information, which are sent to attacker infrastructure. This can lead to credential theft, unauthorized access, and further compromise of the victim's environment. The impact activates immediately upon using the SDK's documented API calls.
Mitigation Recommendations
No official patch or remediation is currently available for this malicious package. The best mitigation is to avoid using the 'paysafe-fraud' package version 1.0.0 entirely. Verify package authenticity before installation by checking the official Paysafe repositories and using trusted sources. Remove any instances of this package from your environment and audit for potential credential exposure. Monitor for suspicious network traffic to unknown hosts on TCP port 8443.
Malicious code in paysafe-fraud (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (a596646a3604e01bef558573fc7199a2b9e9cc07ab7edae1b7e445d2e2b860b6) Package advertises itself as the 'Paysafe Fraud Prevention SDK' (name paysafe-fraud, repo github.com/paysafe/paysafe-fraud) but the exported PaysafeClient (payments.create/get, customers.create/get) schedules a hidden __exfil() call via setTimeout on every API invocation. __exfil enumerates process.env, filters variables whose names contain XOR-decoded substrings for 'key', 'secret', 'token', 'password', 'auth', and 'api', truncates each value to 100 chars, and combines them with os.hostname(), os.userInfo().username, process.cwd(), a timestamp, the package name, and the first 10 characters of the caller-supplied apiKey. The resulting JSON is POSTed over TCP 8443 to an XOR-obfuscated hardcoded hostname with an XOR-obfuscated path. All sensitive strings (destination host, HTTP method/headers, env-key filters) are decoded at runtime via an __x() XOR routine keyed by a hardcoded base64 blob. A __check() guard aborts exfil when os.cpus().length < 2 or when the hostname/username matches a decoded analyst/sandbox blocklist, indicating deliberate anti-analysis. This is a brand-impersonation typosquat carrying a credential-stealer payload; the harm fires as soon as a consumer application uses the SDK's documented API, delivering caller credentials and host identifiers to attacker infrastructure.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'paysafe-fraud' npm package (version 1.0.0) masquerades as the Paysafe Fraud Prevention SDK but contains a hidden exfiltration function (__exfil) that activates on every API invocation. This function collects environment variables filtered for sensitive keys (e.g., 'key', 'secret', 'token', 'password', 'auth', 'api'), truncates their values, and combines them with host identifiers such as hostname, username, current working directory, a timestamp, the package name, and part of the caller's API key. The collected data is sent via HTTPS POST to an attacker-controlled server with obfuscated hostname and path, decoded at runtime. The package includes anti-analysis logic that aborts exfiltration if the environment appears to be a sandbox or analyst machine (e.g., CPU count less than 2 or blacklisted hostnames/usernames). This is a credential-stealing payload delivered through a brand-impersonation typosquat.
Potential Impact
Use of this package results in the compromise of environment credentials and host information, which are sent to attacker infrastructure. This can lead to credential theft, unauthorized access, and further compromise of the victim's environment. The impact activates immediately upon using the SDK's documented API calls.
Mitigation Recommendations
No official patch or remediation is currently available for this malicious package. The best mitigation is to avoid using the 'paysafe-fraud' package version 1.0.0 entirely. Verify package authenticity before installation by checking the official Paysafe repositories and using trusted sources. Remove any instances of this package from your environment and audit for potential credential exposure. Monitor for suspicious network traffic to unknown hosts on TCP port 8443.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10168
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a520ebf68715ace438f59a3
Added to database: 07/11/2026, 09:37:03 UTC
Last enriched: 07/11/2026, 09:54:30 UTC
Last updated: 07/31/2026, 04:39:44 UTC
Views: 53
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.