Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in rust-testing-utils (npm)

0
Critical
Published: 08/23/2026 (08/23/2026, 03:14:27 UTC)
Source: GCVE Database
Product: rust-testing-utils

Description

The npm package rust-testing-utils version 2.3.0 contains malicious code that impersonates the pino logger. It executes attacker-controlled code fetched from a remote URL by decoding a base64 string stored in a fabricated environment variable. This remote code is executed with full module-loading capabilities, allowing arbitrary code execution within the consumer's process. The malicious payload can change dynamically without requiring a package update, indicating an intentional supply-chain attack.

Affected software

npmghsa
rust-testing-utils
Affected versions
=2.3.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/23/2026, 13:50:13 UTC

Technical Analysis

The rust-testing-utils npm package version 2.3.0 masquerades as the pino logger by mimicking its README, keywords, and API. Its index.js exports middleware that spawns a detached child process running lib/caller.js. This script reconstructs a hardcoded URL by base64-decoding a value stored under a fake process.env variable. It fetches JavaScript code from this URL using axios, then executes the fetched code via the Function constructor with require passed as an argument, granting the remote code arbitrary execution and module-loading capabilities. The remote endpoint is attacker-controlled and mutable, enabling dynamic payload changes without package updates. The obfuscation techniques and impersonation strongly indicate a deliberate supply-chain compromise rather than legitimate functionality.

Potential Impact

Consumers of rust-testing-utils version 2.3.0 are at risk of arbitrary code execution within their runtime environment. The malicious code can load any module and execute any commands with the privileges of the host process. Because the payload is fetched remotely and can be changed at any time by the attacker, the threat is persistent and can evolve without requiring new package versions. This compromises the integrity and security of any system using this package.

Mitigation Recommendations

No official patch or remediation is currently documented. Users should immediately remove and stop using rust-testing-utils version 2.3.0. Avoid installing or deploying this package until a trusted, verified version is released. Monitor vendor advisories and trusted security sources for updates. Since the malicious payload is fetched remotely, network-level blocking of the indicated URL may provide temporary mitigation but does not replace removing the compromised package.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-14374
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a8af9a3acd9273b49f32ef7

Added to database: 08/23/2026, 13:46:11 UTC

Last enriched: 08/23/2026, 13:50:13 UTC

Last updated: 08/24/2026, 00:32:03 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses