Malicious code in theme-color-picker (npm)
The npm package 'theme-color-picker' versions 2.0.28, 2.0.30, and 2.0.31 contains malicious code masquerading as a color picker. Instead of its stated functionality, it includes a Windows dropper that downloads, decrypts, and executes a malicious DLL with persistence via a scheduled task named 'WindowsUpdateService'. The package self-removes from node_modules and the root package.json to evade detection. Systems running npm install on these versions are fully compromised.
AI Analysis
Technical Summary
The 'theme-color-picker' npm package, published by 'analysis-chart.io', contains a malicious payload in lib/picker.js that downloads an attacker-controlled encrypted binary from GitHub, decrypts it using XOR with key 0x42, base64-decodes it, verifies it as a Windows PE file, writes it to %APPDATA%/Microsoft/Windows with a randomized name, and executes it via rundll32. It establishes persistence by creating a scheduled task 'WindowsUpdateService' with highest privileges to relaunch the DLL at logon. Post-installation, it deletes its own files from node_modules and removes its dependency entry from the consumer's root package.json to conceal its presence. The malicious code is triggered automatically during npm install via the scripts.install hook. This results in full system compromise on Windows machines that install these package versions.
Potential Impact
Installation of affected versions on Windows systems leads to execution of attacker-controlled native code with persistence and elevated privileges. The attacker gains full control over the compromised system. Secrets and keys stored on the system may be exposed. The package attempts to hide its presence by self-removal and manifest modification, complicating detection and remediation.
Mitigation Recommendations
No official patch or fix is available. Users should immediately remove the affected package versions (=2.0.28, =2.0.30, =2.0.31) from their projects. Because the malicious payload establishes persistence and full system compromise is likely, affected machines should be considered fully compromised. It is strongly recommended to perform a full system forensic analysis and reinstallation from a trusted source. All secrets and keys stored on the compromised machine must be rotated from a different, secure device. Monitor for suspicious scheduled tasks named 'WindowsUpdateService' and remove them if found. Avoid using this package or any versions from the publisher 'analysis-chart.io'.
Malicious code in theme-color-picker (npm)
Description
The npm package 'theme-color-picker' versions 2.0.28, 2.0.30, and 2.0.31 contains malicious code masquerading as a color picker. Instead of its stated functionality, it includes a Windows dropper that downloads, decrypts, and executes a malicious DLL with persistence via a scheduled task named 'WindowsUpdateService'. The package self-removes from node_modules and the root package.json to evade detection. Systems running npm install on these versions are fully compromised.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'theme-color-picker' npm package, published by 'analysis-chart.io', contains a malicious payload in lib/picker.js that downloads an attacker-controlled encrypted binary from GitHub, decrypts it using XOR with key 0x42, base64-decodes it, verifies it as a Windows PE file, writes it to %APPDATA%/Microsoft/Windows with a randomized name, and executes it via rundll32. It establishes persistence by creating a scheduled task 'WindowsUpdateService' with highest privileges to relaunch the DLL at logon. Post-installation, it deletes its own files from node_modules and removes its dependency entry from the consumer's root package.json to conceal its presence. The malicious code is triggered automatically during npm install via the scripts.install hook. This results in full system compromise on Windows machines that install these package versions.
Potential Impact
Installation of affected versions on Windows systems leads to execution of attacker-controlled native code with persistence and elevated privileges. The attacker gains full control over the compromised system. Secrets and keys stored on the system may be exposed. The package attempts to hide its presence by self-removal and manifest modification, complicating detection and remediation.
Mitigation Recommendations
No official patch or fix is available. Users should immediately remove the affected package versions (=2.0.28, =2.0.30, =2.0.31) from their projects. Because the malicious payload establishes persistence and full system compromise is likely, affected machines should be considered fully compromised. It is strongly recommended to perform a full system forensic analysis and reinstallation from a trusted source. All secrets and keys stored on the compromised machine must be rotated from a different, secure device. Monitor for suspicious scheduled tasks named 'WindowsUpdateService' and remove them if found. Avoid using this package or any versions from the publisher 'analysis-chart.io'.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-6357
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-89wv-9w8v-q55g"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a3ef7bd27e9c79719ffc93b
Added to database: 06/26/2026, 22:05:49 UTC
Last enriched: 06/26/2026, 22:33:27 UTC
Last updated: 07/27/2026, 15:49:33 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.