Malicious code in ssb-test-package (npm)
Description
The [email protected] is a malicious npm package designed as a proof-of-concept for dependency confusion attacks. It includes a preinstall script that executes arbitrary code during installation, collecting host system information and writing it locally. The package lacks legitimate functionality and does not exfiltrate data over the network but demonstrates the risk of code execution via npm install hooks.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
ssb-test-package version 1.0.0 is a proof-of-concept malicious npm package that exploits dependency confusion by using a preinstall hook to run arbitrary code on the host during installation. The preinstall script (poc.js) collects reconnaissance data such as OS user, hostname, platform, architecture, Node.js version, current working directory, and network interface addresses, then writes this data to a local JSON file. The package does not contain any legitimate library code (index.js is missing), and no network exfiltration occurs. This demonstrates the potential for remote code execution (RCE) via npm dependency confusion attacks.
Potential Impact
The package enables arbitrary code execution on the host system at install time, allowing an attacker to gather detailed system reconnaissance data. Although this specific package does not exfiltrate data over the network, the capability to run code during installation poses a significant security risk, potentially leading to further compromise if exploited in a real attack scenario.
Mitigation Recommendations
No official patch or remediation is available for this package as it is a proof-of-concept malicious package. Users should avoid installing [email protected] or any similarly suspicious packages, especially those with unexpected or undocumented preinstall scripts. Employ strict dependency management and verification practices to prevent dependency confusion attacks. Monitor package sources carefully and use tools that detect malicious or unexpected install scripts.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-14221
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a85b4c7acd9273b4925282f
Added to database: 08/19/2026, 13:51:03 UTC
Last enriched: 08/19/2026, 14:37:44 UTC
Last updated: 10/02/2026, 13:52:27 UTC
Views: 25
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.