Skip to main content

Malicious code in poc-ch4rlygr (npm)

0
Critical
Published: 08/06/2026 (08/06/2026, 19:09:42 UTC)
Source: GCVE Database
Product: poc-ch4rlygr

Description

The npm package poc-ch4rlygr contains malicious code that exfiltrates sensitive environment information upon import or require. It collects system details and environment variables, including secrets such as AWS, NPM, GitHub, and CI tokens, and sends them via HTTPS GET to a hardcoded external endpoint. The package also declares a postinstall script that is not included in the tarball, indicating the import-time code is the main exfiltration vector.

Affected software

npmghsa
poc-ch4rlygr
Affected versions
=1.5.0=1.3.0=1.4.0=1.2.0=1.1.0=1.6.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/07/2026, 07:32:49 UTC

Technical Analysis

The poc-ch4rlygr npm package versions 1.1.0, 1.2.0, 1.3.0, 1.4.0, 1.5.0, and 1.6.0 contain malicious code in index.js that, when the package is imported or required, collects os.hostname(), os.arch(), __dirname, os.userInfo().username, and the full process.env contents. This data is serialized and sent as a query string via HTTPS GET to a hardcoded Burp Collaborator/OAST subdomain (zuxsp9k9vyk5y45z1n2hv0orhin9b2zr.oastify.com), effectively leaking any secrets present in the environment at load time. The package.json declares a postinstall script 'node tu-script.js', but this script is not included in the package tarball, confirming that the import-time code is the operative exfiltration mechanism.

Potential Impact

Sensitive environment variables and system information, including potentially critical secrets such as AWS credentials, NPM tokens, GitHub tokens, and CI provider tokens, are leaked to an external attacker-controlled server upon package import. This can lead to unauthorized access to cloud resources, code repositories, and continuous integration environments, posing a significant security risk to affected users.

Mitigation Recommendations

No official patch or remediation is currently documented. Users should immediately stop using the affected versions of the poc-ch4rlygr package (1.1.0 through 1.6.0) and remove it from their projects. Avoid installing or importing this package until a trusted, clean version is available. Monitor for any unauthorized access that could result from leaked credentials. Patch status is not yet confirmed — check the vendor or repository advisory for current remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13454
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6a7573b5bf8831d539d93baa

Added to database: 08/07/2026, 05:57:09 UTC

Last enriched: 08/07/2026, 07:32:49 UTC

Last updated: 09/21/2026, 23:01:44 UTC

Views: 25

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses