Skip to main content

Malicious code in sw-pluginer (npm)

0
Critical
Published: 08/19/2026 (08/19/2026, 02:49:26 UTC)
Source: GCVE Database
Product: sw-pluginer

Description

The npm package sw-pluginer masquerades as a Tailwind plugin but contains malicious code that executes arbitrary JavaScript fetched from a URL specified in a transient manifest.json file. This file is staged in node_modules/.bin and deleted after reading, concealing the payload source. The fetched code is executed via eval() in the Node.js build environment without any integrity checks, enabling remote code execution on the developer's machine during build time.

Affected software

npmghsa
sw-pluginer
Affected versions
=1.1.0=1.0.2=1.2.0=1.0.1=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/19/2026, 14:39:08 UTC

Technical Analysis

sw-pluginer is a malicious npm package that pretends to be a Tailwind plugin for service worker registration. Its main export reads a URL from a staged manifest.json file located at node_modules/.bin/, which is written by a separate dropper component and deleted after use. It performs an HTTP GET request to the URL and directly executes the response body using eval() in the Node.js environment during the build process. The fetched code is neither pinned, hashed, nor signature-verified, allowing an attacker controlling the manifest.json URL to achieve arbitrary code execution on the developer's machine. The use of a self-deleting manifest file and eval of untrusted network code constitutes a covert dropper mechanism rather than legitimate service worker registration functionality.

Potential Impact

An attacker who controls the URL in the staged manifest.json can execute arbitrary code on the developer's machine at build time. This leads to a full compromise of the development environment, potentially allowing theft of credentials, insertion of further malicious code, or disruption of the build process. Because the malicious code runs in the Node.js environment, it has the same privileges as the developer running the build.

Mitigation Recommendations

No official patch or remediation is currently documented. Users should immediately remove sw-pluginer from their dependencies and avoid installing or running builds that include this package. Verify all dependencies for authenticity and integrity before use. Since the malicious behavior relies on a staged manifest.json file and network-fetched code, monitoring for unexpected files in node_modules/.bin and network activity during builds may help detect exploitation attempts. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-14211
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6a85b4c7acd9273b49252847

Added to database: 08/19/2026, 13:51:03 UTC

Last enriched: 08/19/2026, 14:39:08 UTC

Last updated: 10/03/2026, 19:53:48 UTC

Views: 25

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses