Skip to main content

Malicious code in ssb-test-package (npm)

0
High
Published: 08/19/2026 (08/19/2026, 03:02:26 UTC)
Source: GCVE Database
Product: ssb-test-package

Description

The [email protected] is a malicious npm package designed as a proof-of-concept for dependency confusion attacks. It includes a preinstall script that executes arbitrary code during installation, collecting host system information and writing it locally. The package lacks legitimate functionality and does not exfiltrate data over the network but demonstrates the risk of code execution via npm install hooks.

Affected software

npmghsa
ssb-test-package
Affected versions
=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/19/2026, 14:37:44 UTC

Technical Analysis

ssb-test-package version 1.0.0 is a proof-of-concept malicious npm package that exploits dependency confusion by using a preinstall hook to run arbitrary code on the host during installation. The preinstall script (poc.js) collects reconnaissance data such as OS user, hostname, platform, architecture, Node.js version, current working directory, and network interface addresses, then writes this data to a local JSON file. The package does not contain any legitimate library code (index.js is missing), and no network exfiltration occurs. This demonstrates the potential for remote code execution (RCE) via npm dependency confusion attacks.

Potential Impact

The package enables arbitrary code execution on the host system at install time, allowing an attacker to gather detailed system reconnaissance data. Although this specific package does not exfiltrate data over the network, the capability to run code during installation poses a significant security risk, potentially leading to further compromise if exploited in a real attack scenario.

Mitigation Recommendations

No official patch or remediation is available for this package as it is a proof-of-concept malicious package. Users should avoid installing [email protected] or any similarly suspicious packages, especially those with unexpected or undocumented preinstall scripts. Employ strict dependency management and verification practices to prevent dependency confusion attacks. Monitor package sources carefully and use tools that detect malicious or unexpected install scripts.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-14221
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6a85b4c7acd9273b4925282f

Added to database: 08/19/2026, 13:51:03 UTC

Last enriched: 08/19/2026, 14:37:44 UTC

Last updated: 10/02/2026, 13:52:27 UTC

Views: 25

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses