Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in test_adminet (npm)

0
Critical
Published: 07/13/2026 (07/13/2026, 21:59:21 UTC)
Source: GCVE Database
Product: test_adminet

Description

The npm package 'test_adminet' version 99.9.9 contains malicious code that executes automatically during installation. It runs a preinstall script that collects sensitive system information and files, including local user and host identifiers and contents of /etc/passwd, /etc/hosts, and /etc/shadow. The collected data, including password hashes if run with root privileges, is exfiltrated via a crafted HTTP request to a hardcoded external endpoint. This behavior occurs without user interaction during a standard npm install.

Affected software

npmghsa
test_adminet
Affected versions
=99.9.9

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/14/2026, 09:48:09 UTC

Technical Analysis

The 'test_adminet' npm package version 99.9.9 declares a preinstall hook that executes index.js on installation. This script uses child_process.exec to run a curl POST request sending system identifiers (output of whoami, hostname, id) and the base64-encoded contents of sensitive files (/etc/passwd, /etc/hosts, /etc/shadow) in the User-Agent header to a hardcoded webhook.site URL. The attempt to read /etc/shadow aims to harvest local password hashes, which are transmitted off-host if the installation runs with root privileges, such as in CI or Docker environments. This malicious activity triggers automatically on npm install without requiring user interaction.

Potential Impact

Sensitive system information and password hashes can be exfiltrated to an attacker-controlled endpoint during package installation. If the installation is performed with elevated privileges, the attacker gains access to hashed passwords from /etc/shadow, potentially enabling further compromise. This compromises system confidentiality and integrity.

Mitigation Recommendations

No official patch or remediation is currently documented. Users should avoid installing version 99.9.9 of the 'test_adminet' package. Verify package authenticity before installation and consider using trusted package sources or scanning tools to detect malicious code in dependencies. Monitor for updates or advisories from the package maintainers or npm registry regarding remediation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-10509
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a55ff8e68715ace432f4a7d

Added to database: 07/14/2026, 09:21:18 UTC

Last enriched: 07/14/2026, 09:48:09 UTC

Last updated: 07/22/2026, 20:21:20 UTC

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses