Malicious code in sui-graphql-rpc (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (ba4994f544d3df11fa82980f25dc29e379f25a3e03fdbf9a448e995a75ac76a7) On require('sui-graphql-rpc'), index.js loads lib/telemetry.js which reads ~/.gitconfig from the installer's home directory, extracts the developer's email and name, and uses sha256(identity) as an AES-256-GCM key to attempt decryption of three embedded base64 ciphertext blobs (PROFILES array). Any blob that successfully decrypts yields JavaScript source that is executed via new Function(code)(). Execution is skipped in CI environments, narrowing the attack to developer workstations belonging to a hardcoded victim allowlist. The AES-GCM ciphertext (12-byte IV + 16-byte tag + body) with a key derived from installer-side data prevents recovery of the plaintext payload without possessing a targeted developer's git identity, an intentional evasion of registry scanning. The package's advertised purpose as a GraphQL RPC client does not require reading ~/.gitconfig; the read is used solely to gate arbitrary code execution against selected victims.
Malicious code in sui-graphql-rpc (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (ba4994f544d3df11fa82980f25dc29e379f25a3e03fdbf9a448e995a75ac76a7) On require('sui-graphql-rpc'), index.js loads lib/telemetry.js which reads ~/.gitconfig from the installer's home directory, extracts the developer's email and name, and uses sha256(identity) as an AES-256-GCM key to attempt decryption of three embedded base64 ciphertext blobs (PROFILES array). Any blob that successfully decrypts yields JavaScript source that is executed via new Function(code)(). Execution is skipped in CI environments, narrowing the attack to developer workstations belonging to a hardcoded victim allowlist. The AES-GCM ciphertext (12-byte IV + 16-byte tag + body) with a key derived from installer-side data prevents recovery of the plaintext payload without possessing a targeted developer's git identity, an intentional evasion of registry scanning. The package's advertised purpose as a GraphQL RPC client does not require reading ~/.gitconfig; the read is used solely to gate arbitrary code execution against selected victims.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-14210
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a85b4c7acd9273b4925284b
Added to database: 08/19/2026, 13:51:03 UTC
Last updated: 08/19/2026, 13:51:35 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.