Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in route-processor (npm)

0
Critical
Published: 07/13/2026 (07/13/2026, 19:46:50 UTC)
Source: GCVE Database
Product: route-processor

Description

The npm package 'route-processor' version 3.1.5 contains malicious code that fetches and executes arbitrary JavaScript from a concealed remote URL. This code runs with full Node.js capabilities, including access to require, process, and filesystem modules. The package also includes suspicious dependencies used to harvest browser-stored credentials and fingerprint the host machine, which are unrelated to its advertised functionality. This behavior enables remote code execution and credential theft on any system using this package version.

Affected software

npmghsa
route-processor
Affected versions
=3.1.5

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/14/2026, 09:53:39 UTC

Technical Analysis

The 'route-processor' npm package version 3.1.5 exports a default function that dynamically constructs a URL to fetch JSON data from a remote host (https://svganchordev.net/icons/107). It then extracts a field from the response and executes it as JavaScript code with full Node.js privileges, including require and process access. The package includes dependencies (@primno/dpapi, better-sqlite3, sqlite3, node-machine-id) that facilitate decryption of browser-protected secrets, reading browser login data and cookies, and host fingerprinting. These dependencies serve no legitimate purpose for the advertised React helper functionality and indicate intent to harvest sensitive credentials from the victim's machine. The remote code execution vector is concealed by assembling the URL from split string constants to evade detection.

Potential Impact

Any user or system running 'route-processor' version 3.1.5 and invoking its default export will execute attacker-controlled JavaScript code with full Node.js privileges. This enables arbitrary code execution, including reading sensitive browser data such as login credentials and cookies, decrypting protected secrets on Windows, and collecting host fingerprinting information. This compromises the confidentiality and integrity of the affected system and user data.

Mitigation Recommendations

No official patch or remediation is currently documented for this malicious package version. Users should immediately remove 'route-processor' version 3.1.5 from their projects and dependency trees. Avoid installing or using this package version. Monitor for any updates or advisories from trusted sources regarding remediation. Since this is a malicious package, consider auditing your environment for potential compromise if this package was used.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-10483
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a55ffa268715ace432f733c

Added to database: 07/14/2026, 09:21:38 UTC

Last enriched: 07/14/2026, 09:53:39 UTC

Last updated: 07/23/2026, 11:16:40 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses