Malicious code in remote_session_elements (npm)
The npm package remote_session_elements version 9999.0.0 is a dependency confusion squat designed to override an internal package. It executes a preinstall script that collects environment details such as hostname, username, working directory, npm registry, and CI repository identifiers, then sends this data unencrypted to a remote IP address. This behavior enables external actors to gather reconnaissance information for further dependency confusion attacks targeting internal package namespaces.
AI Analysis
Technical Summary
The malicious npm package [email protected] contains a preinstall script that runs node callback.js. This script collects sensitive environment information including os.hostname(), os.userInfo().username, current working directory, npm registry URL, and CI environment repository identifiers (e.g., GITHUB_REPOSITORY). It transmits this data via an unencrypted HTTP GET request to a hardcoded IP address (http://75.119.137.232:31337/depconfuse?pkg=...), allowing an attacker to identify internal package names, host identities, and CI repository slugs. This reconnaissance facilitates further dependency confusion attacks against the victim's internal package namespace by revealing valuable internal environment details.
Potential Impact
An attacker controlling the remote endpoint can collect sensitive environment information from any system that installs this malicious package version. This includes internal package names, hostnames, usernames, npm registry configurations, and CI repository identifiers. Such data leakage can enable targeted dependency confusion attacks, potentially compromising internal package integrity and supply chain security.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid installing the remote_session_elements package version 9999.0.0. Verify package authenticity before installation and restrict usage of untrusted or suspicious packages. Monitor for and remove any instances of this malicious package in your environments. Patch status is not yet confirmed — check the vendor advisory or trusted sources for updates.
Malicious code in remote_session_elements (npm)
Description
The npm package remote_session_elements version 9999.0.0 is a dependency confusion squat designed to override an internal package. It executes a preinstall script that collects environment details such as hostname, username, working directory, npm registry, and CI repository identifiers, then sends this data unencrypted to a remote IP address. This behavior enables external actors to gather reconnaissance information for further dependency confusion attacks targeting internal package namespaces.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The malicious npm package [email protected] contains a preinstall script that runs node callback.js. This script collects sensitive environment information including os.hostname(), os.userInfo().username, current working directory, npm registry URL, and CI environment repository identifiers (e.g., GITHUB_REPOSITORY). It transmits this data via an unencrypted HTTP GET request to a hardcoded IP address (http://75.119.137.232:31337/depconfuse?pkg=...), allowing an attacker to identify internal package names, host identities, and CI repository slugs. This reconnaissance facilitates further dependency confusion attacks against the victim's internal package namespace by revealing valuable internal environment details.
Potential Impact
An attacker controlling the remote endpoint can collect sensitive environment information from any system that installs this malicious package version. This includes internal package names, hostnames, usernames, npm registry configurations, and CI repository identifiers. Such data leakage can enable targeted dependency confusion attacks, potentially compromising internal package integrity and supply chain security.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid installing the remote_session_elements package version 9999.0.0. Verify package authenticity before installation and restrict usage of untrusted or suspicious packages. Monitor for and remove any instances of this malicious package in your environments. Patch status is not yet confirmed — check the vendor advisory or trusted sources for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12427
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a735743bf8831d539159c62
Added to database: 08/05/2026, 15:31:15 UTC
Last enriched: 08/05/2026, 17:17:59 UTC
Last updated: 08/05/2026, 17:17:59 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.