Malicious code in telemetry-metrics (npm)
The telemetry-metrics npm package versions 0.2.1, 0.2.3, and 0.2.5 contain malicious code that downloads and executes a binary from an untrusted, mutable GitHub branch. This binary is saved to a Windows system directory and executed automatically during normal library usage on Windows hosts. The package impersonates a legitimate telemetry project but includes unauthorized code that performs this harmful action.
AI Analysis
Technical Summary
The telemetry-metrics npm package, published as an unscoped package while referencing the legitimate @telemetry-js/telemetry project, contains injected malicious code in versions 0.2.1, 0.2.3, and 0.2.5. The malicious code adds a plugin-options.js file that fetches a binary executable from a mutable branch on an unrelated personal GitHub repository. This binary is saved to C:\Windows\http-axios.exe and executed via child_process.execFile on every plugin registration path, causing automatic execution on Windows systems. The fetched binary is neither hashed nor pinned, increasing risk. This behavior effectively results in a drop-and-run malware infection vector embedded within a seemingly legitimate npm package.
Potential Impact
Systems running affected telemetry-metrics package versions on Windows will automatically download and execute an untrusted binary in a system directory, potentially leading to arbitrary code execution and system compromise. The malicious binary source is uncontrolled and mutable, increasing the risk of further malicious payloads. This compromises the security and integrity of affected hosts.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately stop using the affected telemetry-metrics package versions (=0.2.1, =0.2.3, =0.2.5). Remove any installations of this package from Windows systems and verify that no unauthorized binaries (such as C:\Windows\http-axios.exe) remain. Monitor for suspicious activity related to this package. Check the vendor or package repository for updates or official advisories before resuming use.
Malicious code in telemetry-metrics (npm)
Description
The telemetry-metrics npm package versions 0.2.1, 0.2.3, and 0.2.5 contain malicious code that downloads and executes a binary from an untrusted, mutable GitHub branch. This binary is saved to a Windows system directory and executed automatically during normal library usage on Windows hosts. The package impersonates a legitimate telemetry project but includes unauthorized code that performs this harmful action.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The telemetry-metrics npm package, published as an unscoped package while referencing the legitimate @telemetry-js/telemetry project, contains injected malicious code in versions 0.2.1, 0.2.3, and 0.2.5. The malicious code adds a plugin-options.js file that fetches a binary executable from a mutable branch on an unrelated personal GitHub repository. This binary is saved to C:\Windows\http-axios.exe and executed via child_process.execFile on every plugin registration path, causing automatic execution on Windows systems. The fetched binary is neither hashed nor pinned, increasing risk. This behavior effectively results in a drop-and-run malware infection vector embedded within a seemingly legitimate npm package.
Potential Impact
Systems running affected telemetry-metrics package versions on Windows will automatically download and execute an untrusted binary in a system directory, potentially leading to arbitrary code execution and system compromise. The malicious binary source is uncontrolled and mutable, increasing the risk of further malicious payloads. This compromises the security and integrity of affected hosts.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately stop using the affected telemetry-metrics package versions (=0.2.1, =0.2.3, =0.2.5). Remove any installations of this package from Windows systems and verify that no unauthorized binaries (such as C:\Windows\http-axios.exe) remain. Monitor for suspicious activity related to this package. Check the vendor or package repository for updates or official advisories before resuming use.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10750
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a73572fbf8831d53913cd2f
Added to database: 08/05/2026, 15:30:55 UTC
Last enriched: 08/19/2026, 16:44:35 UTC
Last updated: 09/11/2026, 15:46:04 UTC
Views: 21
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.