Malicious code in statist-browser-typed-client-eventea.projects.tdeal (npm)
The npm package 'statist-browser-typed-client-eventea.projects.tdeal' version 0.0.1 is identified as malicious. Although no static or behavioral indicators of supply-chain attack patterns were observed, the package is considered fully compromising any computer on which it is installed or running. It is recommended to remove the package and immediately rotate all secrets and keys from a different, uncompromised machine. Complete remediation may require more than just package removal due to potential full system compromise.
AI Analysis
Technical Summary
This threat involves a malicious npm package named 'statist-browser-typed-client-eventea.projects.tdeal' at version 0.0.1. According to Amazon Inspector, the package files do not exhibit typical supply-chain attack behaviors such as lifecycle scripts fetching remote content, credential theft, exfiltration endpoints, obfuscated payloads, or destructive install-time/import-time actions. However, the GHSA malware advisory states that any system with this package installed should be considered fully compromised, implying the package grants full control to an attacker. Immediate secret and key rotation from a separate machine and package removal are advised, but full remediation may require additional steps due to potential persistent compromise.
Potential Impact
Any computer with this package installed or running is considered fully compromised, meaning attackers may have complete control over the system. All secrets and keys stored on the compromised computer are at risk and must be rotated immediately from a different, secure machine. Removing the package alone may not eliminate all malicious software resulting from the installation, indicating a severe impact on system integrity and confidentiality.
Mitigation Recommendations
Remove the 'statist-browser-typed-client-eventea.projects.tdeal' package immediately. Rotate all secrets and keys stored on the compromised system from a different, uncompromised computer. Because the system may be fully compromised, additional remediation steps beyond package removal may be necessary to ensure full system integrity. No official patch or fix is available; remediation relies on removal and secret rotation.
Malicious code in statist-browser-typed-client-eventea.projects.tdeal (npm)
Description
The npm package 'statist-browser-typed-client-eventea.projects.tdeal' version 0.0.1 is identified as malicious. Although no static or behavioral indicators of supply-chain attack patterns were observed, the package is considered fully compromising any computer on which it is installed or running. It is recommended to remove the package and immediately rotate all secrets and keys from a different, uncompromised machine. Complete remediation may require more than just package removal due to potential full system compromise.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves a malicious npm package named 'statist-browser-typed-client-eventea.projects.tdeal' at version 0.0.1. According to Amazon Inspector, the package files do not exhibit typical supply-chain attack behaviors such as lifecycle scripts fetching remote content, credential theft, exfiltration endpoints, obfuscated payloads, or destructive install-time/import-time actions. However, the GHSA malware advisory states that any system with this package installed should be considered fully compromised, implying the package grants full control to an attacker. Immediate secret and key rotation from a separate machine and package removal are advised, but full remediation may require additional steps due to potential persistent compromise.
Potential Impact
Any computer with this package installed or running is considered fully compromised, meaning attackers may have complete control over the system. All secrets and keys stored on the compromised computer are at risk and must be rotated immediately from a different, secure machine. Removing the package alone may not eliminate all malicious software resulting from the installation, indicating a severe impact on system integrity and confidentiality.
Defensive Guidance
Remove the 'statist-browser-typed-client-eventea.projects.tdeal' package immediately. Rotate all secrets and keys stored on the compromised system from a different, uncompromised computer. Because the system may be fully compromised, additional remediation steps beyond package removal may be necessary to ensure full system integrity. No official patch or fix is available; remediation relies on removal and secret rotation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13674
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-966c-8786-6cx7"]
- Ecosystems
- ["npm"]
Threat ID: 6a79f0d3bf8831d539f61019
Added to database: 08/10/2026, 15:40:03 UTC
Last enriched: 08/10/2026, 15:54:28 UTC
Last updated: 09/22/2026, 20:41:06 UTC
Views: 21
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.