Malicious code in route-processor (npm)
The npm package 'route-processor' version 3.1.5 contains malicious code that fetches and executes arbitrary JavaScript from a concealed remote URL. This code runs with full Node.js capabilities, including access to require, process, and filesystem modules. The package also includes suspicious dependencies used to harvest browser-stored credentials and fingerprint the host machine, which are unrelated to its advertised functionality. This behavior enables remote code execution and credential theft on any system using this package version.
AI Analysis
Technical Summary
The 'route-processor' npm package version 3.1.5 exports a default function that dynamically constructs a URL to fetch JSON data from a remote host (https://svganchordev.net/icons/107). It then extracts a field from the response and executes it as JavaScript code with full Node.js privileges, including require and process access. The package includes dependencies (@primno/dpapi, better-sqlite3, sqlite3, node-machine-id) that facilitate decryption of browser-protected secrets, reading browser login data and cookies, and host fingerprinting. These dependencies serve no legitimate purpose for the advertised React helper functionality and indicate intent to harvest sensitive credentials from the victim's machine. The remote code execution vector is concealed by assembling the URL from split string constants to evade detection.
Potential Impact
Any user or system running 'route-processor' version 3.1.5 and invoking its default export will execute attacker-controlled JavaScript code with full Node.js privileges. This enables arbitrary code execution, including reading sensitive browser data such as login credentials and cookies, decrypting protected secrets on Windows, and collecting host fingerprinting information. This compromises the confidentiality and integrity of the affected system and user data.
Mitigation Recommendations
No official patch or remediation is currently documented for this malicious package version. Users should immediately remove 'route-processor' version 3.1.5 from their projects and dependency trees. Avoid installing or using this package version. Monitor for any updates or advisories from trusted sources regarding remediation. Since this is a malicious package, consider auditing your environment for potential compromise if this package was used.
Malicious code in route-processor (npm)
Description
The npm package 'route-processor' version 3.1.5 contains malicious code that fetches and executes arbitrary JavaScript from a concealed remote URL. This code runs with full Node.js capabilities, including access to require, process, and filesystem modules. The package also includes suspicious dependencies used to harvest browser-stored credentials and fingerprint the host machine, which are unrelated to its advertised functionality. This behavior enables remote code execution and credential theft on any system using this package version.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'route-processor' npm package version 3.1.5 exports a default function that dynamically constructs a URL to fetch JSON data from a remote host (https://svganchordev.net/icons/107). It then extracts a field from the response and executes it as JavaScript code with full Node.js privileges, including require and process access. The package includes dependencies (@primno/dpapi, better-sqlite3, sqlite3, node-machine-id) that facilitate decryption of browser-protected secrets, reading browser login data and cookies, and host fingerprinting. These dependencies serve no legitimate purpose for the advertised React helper functionality and indicate intent to harvest sensitive credentials from the victim's machine. The remote code execution vector is concealed by assembling the URL from split string constants to evade detection.
Potential Impact
Any user or system running 'route-processor' version 3.1.5 and invoking its default export will execute attacker-controlled JavaScript code with full Node.js privileges. This enables arbitrary code execution, including reading sensitive browser data such as login credentials and cookies, decrypting protected secrets on Windows, and collecting host fingerprinting information. This compromises the confidentiality and integrity of the affected system and user data.
Mitigation Recommendations
No official patch or remediation is currently documented for this malicious package version. Users should immediately remove 'route-processor' version 3.1.5 from their projects and dependency trees. Avoid installing or using this package version. Monitor for any updates or advisories from trusted sources regarding remediation. Since this is a malicious package, consider auditing your environment for potential compromise if this package was used.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10483
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a55ffa268715ace432f733c
Added to database: 07/14/2026, 09:21:38 UTC
Last enriched: 07/14/2026, 09:53:39 UTC
Last updated: 07/23/2026, 11:16:40 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.