Malicious code in statist-browser-typed-client-eventea.projects.tdevice (npm)
The npm package statist-browser-typed-client-eventea.projects.tdevice version 0.0.1 is identified as malicious. Although the package contains only two files and does not exhibit typical installer-time malicious behaviors such as credential access, network exfiltration, or backdoors, its presence on a system indicates a full compromise. Systems with this package installed should be considered fully compromised, and all secrets and keys on the system should be rotated from a different, clean computer. Removing the package alone may not eliminate all malicious software resulting from its installation.
AI Analysis
Technical Summary
The npm package [email protected] is flagged as malicious. Analysis shows it contains only two files without direct evidence of credential theft, network exfiltration, or installer-time malicious scripts. However, the presence of this package on a system is considered a full compromise, implying that an attacker may have gained control beyond what is visible in the package contents. Consequently, all secrets and keys stored on the affected system should be rotated from a separate, uncompromised machine. Removal of the package is recommended but may not fully remediate the compromise.
Potential Impact
Any computer with this package installed or running should be treated as fully compromised. Attackers may have gained control of the system, putting all stored secrets and keys at risk. There is no guarantee that removing the package will remove all malicious components introduced by its installation, potentially allowing persistent unauthorized access.
Mitigation Recommendations
Remove the malicious package immediately. Rotate all secrets and keys stored on the affected system from a different, clean computer. Because the system is considered fully compromised, assume that additional malicious software may be present and conduct a thorough investigation and remediation beyond just removing the package.
Malicious code in statist-browser-typed-client-eventea.projects.tdevice (npm)
Description
The npm package statist-browser-typed-client-eventea.projects.tdevice version 0.0.1 is identified as malicious. Although the package contains only two files and does not exhibit typical installer-time malicious behaviors such as credential access, network exfiltration, or backdoors, its presence on a system indicates a full compromise. Systems with this package installed should be considered fully compromised, and all secrets and keys on the system should be rotated from a different, clean computer. Removing the package alone may not eliminate all malicious software resulting from its installation.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The npm package [email protected] is flagged as malicious. Analysis shows it contains only two files without direct evidence of credential theft, network exfiltration, or installer-time malicious scripts. However, the presence of this package on a system is considered a full compromise, implying that an attacker may have gained control beyond what is visible in the package contents. Consequently, all secrets and keys stored on the affected system should be rotated from a separate, uncompromised machine. Removal of the package is recommended but may not fully remediate the compromise.
Potential Impact
Any computer with this package installed or running should be treated as fully compromised. Attackers may have gained control of the system, putting all stored secrets and keys at risk. There is no guarantee that removing the package will remove all malicious components introduced by its installation, potentially allowing persistent unauthorized access.
Defensive Guidance
Remove the malicious package immediately. Rotate all secrets and keys stored on the affected system from a different, clean computer. Because the system is considered fully compromised, assume that additional malicious software may be present and conduct a thorough investigation and remediation beyond just removing the package.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13675
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-rrvf-xjx8-gmjh"]
- Ecosystems
- ["npm"]
Threat ID: 6a79f0d3bf8831d539f61015
Added to database: 08/10/2026, 15:40:03 UTC
Last enriched: 08/10/2026, 15:54:18 UTC
Last updated: 09/22/2026, 20:10:48 UTC
Views: 19
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.