Malicious code in poc-ch4rlygr (npm)
The npm package poc-ch4rlygr contains malicious code that exfiltrates sensitive environment information upon import or require. It collects system details and environment variables, including secrets such as AWS, NPM, GitHub, and CI tokens, and sends them via HTTPS GET to a hardcoded external endpoint. The package also declares a postinstall script that is not included in the tarball, indicating the import-time code is the main exfiltration vector.
AI Analysis
Technical Summary
The poc-ch4rlygr npm package versions 1.1.0, 1.2.0, 1.3.0, 1.4.0, 1.5.0, and 1.6.0 contain malicious code in index.js that, when the package is imported or required, collects os.hostname(), os.arch(), __dirname, os.userInfo().username, and the full process.env contents. This data is serialized and sent as a query string via HTTPS GET to a hardcoded Burp Collaborator/OAST subdomain (zuxsp9k9vyk5y45z1n2hv0orhin9b2zr.oastify.com), effectively leaking any secrets present in the environment at load time. The package.json declares a postinstall script 'node tu-script.js', but this script is not included in the package tarball, confirming that the import-time code is the operative exfiltration mechanism.
Potential Impact
Sensitive environment variables and system information, including potentially critical secrets such as AWS credentials, NPM tokens, GitHub tokens, and CI provider tokens, are leaked to an external attacker-controlled server upon package import. This can lead to unauthorized access to cloud resources, code repositories, and continuous integration environments, posing a significant security risk to affected users.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately stop using the affected versions of the poc-ch4rlygr package (1.1.0 through 1.6.0) and remove it from their projects. Avoid installing or importing this package until a trusted, clean version is available. Monitor for any unauthorized access that could result from leaked credentials. Patch status is not yet confirmed — check the vendor or repository advisory for current remediation guidance.
Malicious code in poc-ch4rlygr (npm)
Description
The npm package poc-ch4rlygr contains malicious code that exfiltrates sensitive environment information upon import or require. It collects system details and environment variables, including secrets such as AWS, NPM, GitHub, and CI tokens, and sends them via HTTPS GET to a hardcoded external endpoint. The package also declares a postinstall script that is not included in the tarball, indicating the import-time code is the main exfiltration vector.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The poc-ch4rlygr npm package versions 1.1.0, 1.2.0, 1.3.0, 1.4.0, 1.5.0, and 1.6.0 contain malicious code in index.js that, when the package is imported or required, collects os.hostname(), os.arch(), __dirname, os.userInfo().username, and the full process.env contents. This data is serialized and sent as a query string via HTTPS GET to a hardcoded Burp Collaborator/OAST subdomain (zuxsp9k9vyk5y45z1n2hv0orhin9b2zr.oastify.com), effectively leaking any secrets present in the environment at load time. The package.json declares a postinstall script 'node tu-script.js', but this script is not included in the package tarball, confirming that the import-time code is the operative exfiltration mechanism.
Potential Impact
Sensitive environment variables and system information, including potentially critical secrets such as AWS credentials, NPM tokens, GitHub tokens, and CI provider tokens, are leaked to an external attacker-controlled server upon package import. This can lead to unauthorized access to cloud resources, code repositories, and continuous integration environments, posing a significant security risk to affected users.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately stop using the affected versions of the poc-ch4rlygr package (1.1.0 through 1.6.0) and remove it from their projects. Avoid installing or importing this package until a trusted, clean version is available. Monitor for any unauthorized access that could result from leaked credentials. Patch status is not yet confirmed — check the vendor or repository advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13454
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a7573b5bf8831d539d93baa
Added to database: 08/07/2026, 05:57:09 UTC
Last enriched: 08/07/2026, 07:32:49 UTC
Last updated: 09/21/2026, 23:01:44 UTC
Views: 25
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.