Malicious code in tfjs-custom-module (npm)
Description
The tfjs-custom-module npm package is a typosquatting malicious package impersonating the tensorflow/tfjs package. It contains a postinstall script that automatically runs on installation and collects host system identifiers such as hostname, platform, architecture, Node.js version, package name, and npm lifecycle event. This data is exfiltrated via an HTTPS POST request to a hardcoded external domain controlled by the attacker. This behavior constitutes unauthorized host reconnaissance and data exfiltration without user consent.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The tfjs-custom-module package is a malicious typosquatting npm package mimicking the legitimate tensorflow/tfjs package. Its package.json includes a postinstall lifecycle script that executes automatically during npm install. This script gathers system identifiers including os.hostname(), process.platform, process.arch, process.version, the package name, and the npm lifecycle event. It then sends this information as JSON via an HTTPS POST request to a hardcoded external endpoint (8xq4kw5d.instances.poc.jchunt.top/tfjs-custom-module), which is not affiliated with the legitimate package infrastructure. This activity is unauthorized host reconnaissance and data exfiltration to an attacker-controlled server, regardless of any claims of security research.
Potential Impact
The malicious postinstall script leaks sensitive host environment information to an attacker-controlled external server. This can lead to privacy violations and may facilitate further targeted attacks by revealing system details. There is no indication of remote code execution or direct system compromise beyond the data exfiltration described. No known exploits in the wild have been reported.
Mitigation Recommendations
Users should avoid installing the tfjs-custom-module package, as it is a malicious typosquat. There is no official patch or fix since this is a malicious package rather than a vulnerability in legitimate software. Use verified package names and sources when installing npm packages. Consider scanning installed packages for known malicious modules and remove any instances of tfjs-custom-module =1.0.0. Monitor for suspicious network activity related to the described external domain.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-14196
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a85b4c7acd9273b49252882
Added to database: 08/19/2026, 13:51:03 UTC
Last enriched: 08/19/2026, 14:42:29 UTC
Last updated: 10/02/2026, 13:52:40 UTC
Views: 37
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.