Skip to main content

Malicious code in telemetry-metrics (npm)

0
Critical
Published: 07/16/2026 (07/16/2026, 18:45:17 UTC)
Source: GCVE Database
Product: telemetry-metrics

Description

The telemetry-metrics npm package versions 0.2.1, 0.2.3, and 0.2.5 contain malicious code that downloads and executes a binary from an untrusted, mutable GitHub branch. This binary is saved to a Windows system directory and executed automatically during normal library usage on Windows hosts. The package impersonates a legitimate telemetry project but includes unauthorized code that performs this harmful action.

Affected software

npmghsa
telemetry-metrics
Affected versions
=0.2.1=0.2.5=0.2.3

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/19/2026, 16:44:35 UTC

Technical Analysis

The telemetry-metrics npm package, published as an unscoped package while referencing the legitimate @telemetry-js/telemetry project, contains injected malicious code in versions 0.2.1, 0.2.3, and 0.2.5. The malicious code adds a plugin-options.js file that fetches a binary executable from a mutable branch on an unrelated personal GitHub repository. This binary is saved to C:\Windows\http-axios.exe and executed via child_process.execFile on every plugin registration path, causing automatic execution on Windows systems. The fetched binary is neither hashed nor pinned, increasing risk. This behavior effectively results in a drop-and-run malware infection vector embedded within a seemingly legitimate npm package.

Potential Impact

Systems running affected telemetry-metrics package versions on Windows will automatically download and execute an untrusted binary in a system directory, potentially leading to arbitrary code execution and system compromise. The malicious binary source is uncontrolled and mutable, increasing the risk of further malicious payloads. This compromises the security and integrity of affected hosts.

Mitigation Recommendations

No official patch or remediation is currently documented. Users should immediately stop using the affected telemetry-metrics package versions (=0.2.1, =0.2.3, =0.2.5). Remove any installations of this package from Windows systems and verify that no unauthorized binaries (such as C:\Windows\http-axios.exe) remain. Monitor for suspicious activity related to this package. Check the vendor or package repository for updates or official advisories before resuming use.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-10750
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6a73572fbf8831d53913cd2f

Added to database: 08/05/2026, 15:30:55 UTC

Last enriched: 08/19/2026, 16:44:35 UTC

Last updated: 09/11/2026, 15:46:04 UTC

Views: 21

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses