Malicious code in transform-es2015-unicode-regex (npm)
The npm package 'transform-es2015-unicode-regex' version 6.24.1 is a malicious package that impersonates a legitimate Babel plugin by using a similar name. It declares a dependency on a third-party HTTP URL unrelated to the official registry, causing npm install to fetch and execute arbitrary code from an unauthenticated, unencrypted source. This enables arbitrary code execution at install time controlled by the attacker. The package's main code is not the expected Babel plugin but contains code labeled for security research testing purposes, increasing the risk of accidental installation.
AI Analysis
Technical Summary
This threat involves a malicious npm package named 'transform-es2015-unicode-regex' version 6.24.1 that mimics the legitimate Babel plugin of a similar name. The package.json specifies a dependency from a non-official, plain HTTP third-party host (http://pack.nppacks.com), which is unrelated to the legitimate npm registry. When users run 'npm install', the package manager fetches a tarball from this untrusted source over an unencrypted channel, allowing the attacker to execute arbitrary code during installation via lifecycle scripts. The package's index.js does not contain the legitimate plugin code but instead includes code marked as 'Security Research Testing Purpose', indicating malicious intent and increasing the risk of inadvertent compromise.
Potential Impact
If installed, this package allows an attacker to execute arbitrary code on the system at install time due to lifecycle scripts fetched from an untrusted source over an unauthenticated HTTP connection. This can lead to compromise of the development environment or build systems where the package is installed. The attack vector relies on user or automated systems mistakenly installing this malicious package instead of the legitimate one.
Mitigation Recommendations
Users and organizations should avoid installing the 'transform-es2015-unicode-regex' package version 6.24.1 from untrusted sources. Verify package names carefully to avoid typosquatting or impersonation attacks. Use npm's official registry and enable package integrity verification features such as npm audit and package-lock.json. Since no official patch or fix is indicated, the best mitigation is to remove or avoid this malicious package. Monitor dependency manifests for suspicious or unexpected dependencies referencing non-official URLs.
Malicious code in transform-es2015-unicode-regex (npm)
Description
The npm package 'transform-es2015-unicode-regex' version 6.24.1 is a malicious package that impersonates a legitimate Babel plugin by using a similar name. It declares a dependency on a third-party HTTP URL unrelated to the official registry, causing npm install to fetch and execute arbitrary code from an unauthenticated, unencrypted source. This enables arbitrary code execution at install time controlled by the attacker. The package's main code is not the expected Babel plugin but contains code labeled for security research testing purposes, increasing the risk of accidental installation.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves a malicious npm package named 'transform-es2015-unicode-regex' version 6.24.1 that mimics the legitimate Babel plugin of a similar name. The package.json specifies a dependency from a non-official, plain HTTP third-party host (http://pack.nppacks.com), which is unrelated to the legitimate npm registry. When users run 'npm install', the package manager fetches a tarball from this untrusted source over an unencrypted channel, allowing the attacker to execute arbitrary code during installation via lifecycle scripts. The package's index.js does not contain the legitimate plugin code but instead includes code marked as 'Security Research Testing Purpose', indicating malicious intent and increasing the risk of inadvertent compromise.
Potential Impact
If installed, this package allows an attacker to execute arbitrary code on the system at install time due to lifecycle scripts fetched from an untrusted source over an unauthenticated HTTP connection. This can lead to compromise of the development environment or build systems where the package is installed. The attack vector relies on user or automated systems mistakenly installing this malicious package instead of the legitimate one.
Mitigation Recommendations
Users and organizations should avoid installing the 'transform-es2015-unicode-regex' package version 6.24.1 from untrusted sources. Verify package names carefully to avoid typosquatting or impersonation attacks. Use npm's official registry and enable package integrity verification features such as npm audit and package-lock.json. Since no official patch or fix is indicated, the best mitigation is to remove or avoid this malicious package. Monitor dependency manifests for suspicious or unexpected dependencies referencing non-official URLs.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13612
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a75f706bf8831d53984e39e
Added to database: 08/07/2026, 15:17:26 UTC
Last enriched: 08/07/2026, 15:19:23 UTC
Last updated: 08/07/2026, 15:19:57 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.