Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in runtimekit (npm)

0
Critical
Published: 06/25/2026 (06/25/2026, 21:55:52 UTC)
Source: GCVE Database
Product: runtimekit

Description

The npm package 'runtimekit' versions 1.0.1 and 1.0.5 contain malicious code that executes arbitrary JavaScript during module load. The package includes an obfuscated self-executing function that decodes hidden strings to dynamically construct and run code with full Node.js privileges. This behavior occurs when requiring 'runtimekit' or 'runtimekit/readonly', allowing the malicious payload to run in-process. The package falsely advertises itself as a validation/runtime utility but embeds a loader with no legitimate purpose for obfuscation. No official patch or remediation guidance is currently provided.

Affected software

npmghsa
runtimekit
Affected versions
=1.0.5=1.0.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/26/2026, 22:44:28 UTC

Technical Analysis

The 'runtimekit' npm package versions 1.0.1 and 1.0.5 include a self-executing Immediately Invoked Function Expression (IIFE) that decodes obfuscated strings to retrieve the Function constructor and dynamically execute arbitrary JavaScript code at module load time. The loader exposes Node.js require and module objects globally to enable the dynamically constructed function to access them outside the module closure. This results in execution of a hidden payload with full Node privileges whenever the package or its 'readonly' submodule is required. The obfuscation and global exposure of Node internals indicate malicious intent, as there is no legitimate reason for such behavior in a runtime utility package. No patch or fix information is provided in the source data.

Potential Impact

Any application or environment that installs and requires 'runtimekit' versions 1.0.1 or 1.0.5 will execute arbitrary, obfuscated JavaScript code with full Node.js privileges. This can lead to compromise of the host environment, unauthorized code execution, data theft, or further malicious activity. The malicious code runs in-process, making detection and containment more difficult. There is no indication of known exploits in the wild yet.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix or official guidance is available, avoid installing or requiring the 'runtimekit' package versions 1.0.1 and 1.0.5. Remove these versions from any environments where they are present. Consider using alternative, trusted packages for runtime or validation utilities. Monitor package sources and supply chain for updates or advisories regarding this package.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-6477
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a3ef7e527e9c79719032b42

Added to database: 06/26/2026, 22:06:29 UTC

Last enriched: 06/26/2026, 22:44:28 UTC

Last updated: 07/31/2026, 15:06:30 UTC

Views: 136

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses