Malicious code in sw-pluginer (npm)
Description
The npm package sw-pluginer masquerades as a Tailwind plugin but contains malicious code that executes arbitrary JavaScript fetched from a URL specified in a transient manifest.json file. This file is staged in node_modules/.bin and deleted after reading, concealing the payload source. The fetched code is executed via eval() in the Node.js build environment without any integrity checks, enabling remote code execution on the developer's machine during build time.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
sw-pluginer is a malicious npm package that pretends to be a Tailwind plugin for service worker registration. Its main export reads a URL from a staged manifest.json file located at node_modules/.bin/, which is written by a separate dropper component and deleted after use. It performs an HTTP GET request to the URL and directly executes the response body using eval() in the Node.js environment during the build process. The fetched code is neither pinned, hashed, nor signature-verified, allowing an attacker controlling the manifest.json URL to achieve arbitrary code execution on the developer's machine. The use of a self-deleting manifest file and eval of untrusted network code constitutes a covert dropper mechanism rather than legitimate service worker registration functionality.
Potential Impact
An attacker who controls the URL in the staged manifest.json can execute arbitrary code on the developer's machine at build time. This leads to a full compromise of the development environment, potentially allowing theft of credentials, insertion of further malicious code, or disruption of the build process. Because the malicious code runs in the Node.js environment, it has the same privileges as the developer running the build.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately remove sw-pluginer from their dependencies and avoid installing or running builds that include this package. Verify all dependencies for authenticity and integrity before use. Since the malicious behavior relies on a staged manifest.json file and network-fetched code, monitoring for unexpected files in node_modules/.bin and network activity during builds may help detect exploitation attempts. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-14211
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a85b4c7acd9273b49252847
Added to database: 08/19/2026, 13:51:03 UTC
Last enriched: 08/19/2026, 14:39:08 UTC
Last updated: 10/03/2026, 19:53:48 UTC
Views: 25
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.