Malicious code in table-ui-new (npm)
The npm package table-ui-new version 2.7.2 and 2.7.5 contains malicious code embedded in its dist/config.js file, exposed via the package.json './config' subpath export. This export includes an array named HASHES with base64-encoded strings that decode to immediately-invoked async functions which fetch and evaluate remote JavaScript from an attacker-controlled Vercel host. While the main module does not invoke these payloads, any consumer importing the config export receives executable payloads capable of running arbitrary code with full privileges in the Node.js environment. This behavior is unrelated to the package's intended React UI functionality and represents a critical security risk.
AI Analysis
Technical Summary
The npm package table-ui-new versions 2.7.2 and 2.7.5 ship a dist/config.js module that exports an array named HASHES containing four base64-encoded strings. Each string decodes to an immediately-invoked async function expression that fetches JavaScript code from a hardcoded external URL (https://everydaynodechecker-39147n.vercel.app/api/key?mem=root[0-3]) and evaluates it via eval(). This results in unconditional remote code execution in the consumer's Node.js process with full host privileges. The malicious payload is disguised as inert data and is exposed through a public subpath export, posing a severe risk to any project importing this module. The main entry point does not invoke these payloads, but the presence of this export enables exploitation.
Potential Impact
Any consumer of the table-ui-new package that imports the './config' subpath will receive an array of executable payloads that fetch and run attacker-controlled JavaScript code with full privileges in the Node.js environment. This allows remote code execution, potentially leading to full system compromise, data theft, or further malicious activity. The malicious code is unrelated to the package's intended functionality and is hidden behind a misleading variable name, increasing the risk of unnoticed exploitation.
Mitigation Recommendations
No official patch or remediation is currently documented. Consumers should avoid importing the './config' subpath from table-ui-new versions 2.7.2 and 2.7.5. It is recommended to audit dependencies for this package and remove or replace it until a trusted, clean version is available. Monitor vendor advisories or npm security notices for updates or official fixes. Since the package is not a cloud service, remediation depends on user action.
Malicious code in table-ui-new (npm)
Description
The npm package table-ui-new version 2.7.2 and 2.7.5 contains malicious code embedded in its dist/config.js file, exposed via the package.json './config' subpath export. This export includes an array named HASHES with base64-encoded strings that decode to immediately-invoked async functions which fetch and evaluate remote JavaScript from an attacker-controlled Vercel host. While the main module does not invoke these payloads, any consumer importing the config export receives executable payloads capable of running arbitrary code with full privileges in the Node.js environment. This behavior is unrelated to the package's intended React UI functionality and represents a critical security risk.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The npm package table-ui-new versions 2.7.2 and 2.7.5 ship a dist/config.js module that exports an array named HASHES containing four base64-encoded strings. Each string decodes to an immediately-invoked async function expression that fetches JavaScript code from a hardcoded external URL (https://everydaynodechecker-39147n.vercel.app/api/key?mem=root[0-3]) and evaluates it via eval(). This results in unconditional remote code execution in the consumer's Node.js process with full host privileges. The malicious payload is disguised as inert data and is exposed through a public subpath export, posing a severe risk to any project importing this module. The main entry point does not invoke these payloads, but the presence of this export enables exploitation.
Potential Impact
Any consumer of the table-ui-new package that imports the './config' subpath will receive an array of executable payloads that fetch and run attacker-controlled JavaScript code with full privileges in the Node.js environment. This allows remote code execution, potentially leading to full system compromise, data theft, or further malicious activity. The malicious code is unrelated to the package's intended functionality and is hidden behind a misleading variable name, increasing the risk of unnoticed exploitation.
Mitigation Recommendations
No official patch or remediation is currently documented. Consumers should avoid importing the './config' subpath from table-ui-new versions 2.7.2 and 2.7.5. It is recommended to audit dependencies for this package and remove or replace it until a trusted, clean version is available. Monitor vendor advisories or npm security notices for updates or official fixes. Since the package is not a cloud service, remediation depends on user action.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12473
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a73572fbf8831d53913cd34
Added to database: 08/05/2026, 15:30:55 UTC
Last enriched: 08/19/2026, 16:44:45 UTC
Last updated: 09/18/2026, 02:24:02 UTC
Views: 19
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.