Malicious code in @sectest429/hello-npm-world (npm)
The npm package @sectest429/hello-npm-world version 1.0.3 contains malicious code in its preinstall lifecycle script. This script executes automatically during installation and performs unauthorized reconnaissance by collecting system information including OS username, hostname, platform/architecture, running processes, and cloud instance metadata. The collected data is written to a local file named exfil.log. Although the current version does not transmit data externally, the behavior is unrelated to the package's advertised functionality and indicates a trojanized package with code execution at install time. The package should be considered fully compromised and removed.
AI Analysis
Technical Summary
The @sectest429/hello-npm-world npm package version 1.0.3 includes a preinstall.js script that runs automatically on npm install. This script collects sensitive system information such as OS username, hostname, platform/architecture, and running processes. It also attempts to access AWS EC2 instance metadata by requesting an IMDSv2 token and fetching the instance ID from the link-local address 169.254.169.254. The collected data is saved locally to exfil.log in the installer's working directory. This behavior is unrelated to the package's advertised 'hello' function and demonstrates a trojanized package executing code at install time. Although no external data exfiltration currently occurs, the reconnaissance and local data collection pose a significant security risk.
Potential Impact
Any system that installs this package version is at high risk of compromise due to unauthorized code execution during installation. The package collects detailed system and cloud instance information without user consent, which could be used for further attacks or lateral movement. The presence of this package indicates a fully compromised environment, and all secrets and keys on the affected system should be considered exposed and rotated immediately. Removing the package alone may not fully remediate the compromise.
Mitigation Recommendations
Immediate removal of the @sectest429/hello-npm-world package version 1.0.3 is recommended. All secrets and keys stored on the affected system should be rotated from a separate, trusted environment. Since the package executes code during installation, assume full system compromise and perform a thorough investigation and remediation. There is no official patch or fix available; avoid using this package version entirely.
Malicious code in @sectest429/hello-npm-world (npm)
Description
The npm package @sectest429/hello-npm-world version 1.0.3 contains malicious code in its preinstall lifecycle script. This script executes automatically during installation and performs unauthorized reconnaissance by collecting system information including OS username, hostname, platform/architecture, running processes, and cloud instance metadata. The collected data is written to a local file named exfil.log. Although the current version does not transmit data externally, the behavior is unrelated to the package's advertised functionality and indicates a trojanized package with code execution at install time. The package should be considered fully compromised and removed.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The @sectest429/hello-npm-world npm package version 1.0.3 includes a preinstall.js script that runs automatically on npm install. This script collects sensitive system information such as OS username, hostname, platform/architecture, and running processes. It also attempts to access AWS EC2 instance metadata by requesting an IMDSv2 token and fetching the instance ID from the link-local address 169.254.169.254. The collected data is saved locally to exfil.log in the installer's working directory. This behavior is unrelated to the package's advertised 'hello' function and demonstrates a trojanized package executing code at install time. Although no external data exfiltration currently occurs, the reconnaissance and local data collection pose a significant security risk.
Potential Impact
Any system that installs this package version is at high risk of compromise due to unauthorized code execution during installation. The package collects detailed system and cloud instance information without user consent, which could be used for further attacks or lateral movement. The presence of this package indicates a fully compromised environment, and all secrets and keys on the affected system should be considered exposed and rotated immediately. Removing the package alone may not fully remediate the compromise.
Mitigation Recommendations
Immediate removal of the @sectest429/hello-npm-world package version 1.0.3 is recommended. All secrets and keys stored on the affected system should be rotated from a separate, trusted environment. Since the package executes code during installation, assume full system compromise and perform a thorough investigation and remediation. There is no official patch or fix available; avoid using this package version entirely.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10478
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a55ffa268715ace432f7345
Added to database: 07/14/2026, 09:21:38 UTC
Last enriched: 09/12/2026, 15:33:02 UTC
Last updated: 09/14/2026, 21:42:07 UTC
Views: 47
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.