Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in theme-color-picker (npm)

0
Critical
Published: 06/23/2026 (06/23/2026, 21:53:28 UTC)
Source: GCVE Database
Product: theme-color-picker

Description

The npm package 'theme-color-picker' versions 2.0.28, 2.0.30, and 2.0.31 contains malicious code masquerading as a color picker. Instead of its stated functionality, it includes a Windows dropper that downloads, decrypts, and executes a malicious DLL with persistence via a scheduled task named 'WindowsUpdateService'. The package self-removes from node_modules and the root package.json to evade detection. Systems running npm install on these versions are fully compromised.

Affected software

npmghsa
theme-color-picker
Affected versions
=2.0.28=2.0.31=2.0.30

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/26/2026, 22:33:27 UTC

Technical Analysis

The 'theme-color-picker' npm package, published by 'analysis-chart.io', contains a malicious payload in lib/picker.js that downloads an attacker-controlled encrypted binary from GitHub, decrypts it using XOR with key 0x42, base64-decodes it, verifies it as a Windows PE file, writes it to %APPDATA%/Microsoft/Windows with a randomized name, and executes it via rundll32. It establishes persistence by creating a scheduled task 'WindowsUpdateService' with highest privileges to relaunch the DLL at logon. Post-installation, it deletes its own files from node_modules and removes its dependency entry from the consumer's root package.json to conceal its presence. The malicious code is triggered automatically during npm install via the scripts.install hook. This results in full system compromise on Windows machines that install these package versions.

Potential Impact

Installation of affected versions on Windows systems leads to execution of attacker-controlled native code with persistence and elevated privileges. The attacker gains full control over the compromised system. Secrets and keys stored on the system may be exposed. The package attempts to hide its presence by self-removal and manifest modification, complicating detection and remediation.

Mitigation Recommendations

No official patch or fix is available. Users should immediately remove the affected package versions (=2.0.28, =2.0.30, =2.0.31) from their projects. Because the malicious payload establishes persistence and full system compromise is likely, affected machines should be considered fully compromised. It is strongly recommended to perform a full system forensic analysis and reinstallation from a trusted source. All secrets and keys stored on the compromised machine must be rotated from a different, secure device. Monitor for suspicious scheduled tasks named 'WindowsUpdateService' and remove them if found. Avoid using this package or any versions from the publisher 'analysis-chart.io'.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-6357
Osv Schema Version
1.7.4
Aliases
["GHSA-89wv-9w8v-q55g"]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a3ef7bd27e9c79719ffc93b

Added to database: 06/26/2026, 22:05:49 UTC

Last enriched: 06/26/2026, 22:33:27 UTC

Last updated: 07/27/2026, 15:49:33 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses