Malicious code in rust-testing-utils (npm)
The npm package rust-testing-utils version 2.3.0 contains malicious code that impersonates the pino logger. It executes attacker-controlled code fetched from a remote URL by decoding a base64 string stored in a fabricated environment variable. This remote code is executed with full module-loading capabilities, allowing arbitrary code execution within the consumer's process. The malicious payload can change dynamically without requiring a package update, indicating an intentional supply-chain attack.
AI Analysis
Technical Summary
The rust-testing-utils npm package version 2.3.0 masquerades as the pino logger by mimicking its README, keywords, and API. Its index.js exports middleware that spawns a detached child process running lib/caller.js. This script reconstructs a hardcoded URL by base64-decoding a value stored under a fake process.env variable. It fetches JavaScript code from this URL using axios, then executes the fetched code via the Function constructor with require passed as an argument, granting the remote code arbitrary execution and module-loading capabilities. The remote endpoint is attacker-controlled and mutable, enabling dynamic payload changes without package updates. The obfuscation techniques and impersonation strongly indicate a deliberate supply-chain compromise rather than legitimate functionality.
Potential Impact
Consumers of rust-testing-utils version 2.3.0 are at risk of arbitrary code execution within their runtime environment. The malicious code can load any module and execute any commands with the privileges of the host process. Because the payload is fetched remotely and can be changed at any time by the attacker, the threat is persistent and can evolve without requiring new package versions. This compromises the integrity and security of any system using this package.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately remove and stop using rust-testing-utils version 2.3.0. Avoid installing or deploying this package until a trusted, verified version is released. Monitor vendor advisories and trusted security sources for updates. Since the malicious payload is fetched remotely, network-level blocking of the indicated URL may provide temporary mitigation but does not replace removing the compromised package.
Malicious code in rust-testing-utils (npm)
Description
The npm package rust-testing-utils version 2.3.0 contains malicious code that impersonates the pino logger. It executes attacker-controlled code fetched from a remote URL by decoding a base64 string stored in a fabricated environment variable. This remote code is executed with full module-loading capabilities, allowing arbitrary code execution within the consumer's process. The malicious payload can change dynamically without requiring a package update, indicating an intentional supply-chain attack.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The rust-testing-utils npm package version 2.3.0 masquerades as the pino logger by mimicking its README, keywords, and API. Its index.js exports middleware that spawns a detached child process running lib/caller.js. This script reconstructs a hardcoded URL by base64-decoding a value stored under a fake process.env variable. It fetches JavaScript code from this URL using axios, then executes the fetched code via the Function constructor with require passed as an argument, granting the remote code arbitrary execution and module-loading capabilities. The remote endpoint is attacker-controlled and mutable, enabling dynamic payload changes without package updates. The obfuscation techniques and impersonation strongly indicate a deliberate supply-chain compromise rather than legitimate functionality.
Potential Impact
Consumers of rust-testing-utils version 2.3.0 are at risk of arbitrary code execution within their runtime environment. The malicious code can load any module and execute any commands with the privileges of the host process. Because the payload is fetched remotely and can be changed at any time by the attacker, the threat is persistent and can evolve without requiring new package versions. This compromises the integrity and security of any system using this package.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately remove and stop using rust-testing-utils version 2.3.0. Avoid installing or deploying this package until a trusted, verified version is released. Monitor vendor advisories and trusted security sources for updates. Since the malicious payload is fetched remotely, network-level blocking of the indicated URL may provide temporary mitigation but does not replace removing the compromised package.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-14374
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a8af9a3acd9273b49f32ef7
Added to database: 08/23/2026, 13:46:11 UTC
Last enriched: 08/23/2026, 13:50:13 UTC
Last updated: 08/24/2026, 00:32:03 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.