Skip to main content

Malicious code in table-ui-new (npm)

0
Critical
Published: 08/05/2026 (08/05/2026, 12:57:24 UTC)
Source: GCVE Database
Product: table-ui-new

Description

The npm package table-ui-new version 2.7.2 and 2.7.5 contains malicious code embedded in its dist/config.js file, exposed via the package.json './config' subpath export. This export includes an array named HASHES with base64-encoded strings that decode to immediately-invoked async functions which fetch and evaluate remote JavaScript from an attacker-controlled Vercel host. While the main module does not invoke these payloads, any consumer importing the config export receives executable payloads capable of running arbitrary code with full privileges in the Node.js environment. This behavior is unrelated to the package's intended React UI functionality and represents a critical security risk.

Affected software

npmghsa
table-ui-new
Affected versions
=2.7.5=2.7.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/19/2026, 16:44:45 UTC

Technical Analysis

The npm package table-ui-new versions 2.7.2 and 2.7.5 ship a dist/config.js module that exports an array named HASHES containing four base64-encoded strings. Each string decodes to an immediately-invoked async function expression that fetches JavaScript code from a hardcoded external URL (https://everydaynodechecker-39147n.vercel.app/api/key?mem=root[0-3]) and evaluates it via eval(). This results in unconditional remote code execution in the consumer's Node.js process with full host privileges. The malicious payload is disguised as inert data and is exposed through a public subpath export, posing a severe risk to any project importing this module. The main entry point does not invoke these payloads, but the presence of this export enables exploitation.

Potential Impact

Any consumer of the table-ui-new package that imports the './config' subpath will receive an array of executable payloads that fetch and run attacker-controlled JavaScript code with full privileges in the Node.js environment. This allows remote code execution, potentially leading to full system compromise, data theft, or further malicious activity. The malicious code is unrelated to the package's intended functionality and is hidden behind a misleading variable name, increasing the risk of unnoticed exploitation.

Mitigation Recommendations

No official patch or remediation is currently documented. Consumers should avoid importing the './config' subpath from table-ui-new versions 2.7.2 and 2.7.5. It is recommended to audit dependencies for this package and remove or replace it until a trusted, clean version is available. Monitor vendor advisories or npm security notices for updates or official fixes. Since the package is not a cloud service, remediation depends on user action.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-12473
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6a73572fbf8831d53913cd34

Added to database: 08/05/2026, 15:30:55 UTC

Last enriched: 08/19/2026, 16:44:45 UTC

Last updated: 09/18/2026, 02:24:02 UTC

Views: 19

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses