Malicious code in trimprompt (npm)
The npm package trimprompt versions 1.0.35, 1.0.42, 1.0.46, 1.0.47, 1.0.48, and 1.0.49 contains heavily obfuscated JavaScript modules that execute malicious behavior. These modules include scripts that spawn PowerShell processes during installation and runtime on Windows hosts, and perform HTTP POST requests sending host identifiers to remote endpoints. This behavior is inconsistent with the package's intended functionality and indicates a supply-chain compromise with install-time execution and host beaconing capabilities.
AI Analysis
Technical Summary
The trimprompt npm package versions 1.0.35, 1.0.42, 1.0.46, 1.0.47, 1.0.48, and 1.0.49 include multiple heavily obfuscated JavaScript files. Two obfuscated modules (sync.js and tracker.js) combine child_process usage with HTTP POST requests that transmit host and identifier information, suggesting host reconnaissance and outbound reporting to remote servers. Additionally, a postinstall.js script executes automatically on npm install, spawning PowerShell processes, and shims.js runs execSync with PowerShell commands, providing execution surfaces at install and load time on Windows. The obfuscation and behavior strongly indicate a malicious supply-chain payload rather than legitimate functionality. Concrete remote endpoints are hidden by string-array obfuscation and not recoverable from the provided data.
Potential Impact
This malicious code can execute arbitrary PowerShell commands on Windows hosts during package installation and runtime, potentially allowing attackers to perform host reconnaissance and exfiltrate identifying information to remote servers. This compromises the security and privacy of affected systems and may facilitate further attacks or persistence. The presence of obfuscated code and outbound beaconing indicates a supply-chain compromise with significant risk to users installing these package versions.
Mitigation Recommendations
No official patch or remediation information is provided. Users should immediately cease using the affected versions of trimprompt (1.0.35, 1.0.42, 1.0.46, 1.0.47, 1.0.48, 1.0.49). It is recommended to audit and remove these versions from environments and replace them with trusted alternatives or versions verified clean by the vendor or community. Monitor for unexpected PowerShell executions and network traffic to unknown endpoints on Windows hosts where these versions were installed. Check the vendor advisory for any updates on remediation.
Malicious code in trimprompt (npm)
Description
The npm package trimprompt versions 1.0.35, 1.0.42, 1.0.46, 1.0.47, 1.0.48, and 1.0.49 contains heavily obfuscated JavaScript modules that execute malicious behavior. These modules include scripts that spawn PowerShell processes during installation and runtime on Windows hosts, and perform HTTP POST requests sending host identifiers to remote endpoints. This behavior is inconsistent with the package's intended functionality and indicates a supply-chain compromise with install-time execution and host beaconing capabilities.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The trimprompt npm package versions 1.0.35, 1.0.42, 1.0.46, 1.0.47, 1.0.48, and 1.0.49 include multiple heavily obfuscated JavaScript files. Two obfuscated modules (sync.js and tracker.js) combine child_process usage with HTTP POST requests that transmit host and identifier information, suggesting host reconnaissance and outbound reporting to remote servers. Additionally, a postinstall.js script executes automatically on npm install, spawning PowerShell processes, and shims.js runs execSync with PowerShell commands, providing execution surfaces at install and load time on Windows. The obfuscation and behavior strongly indicate a malicious supply-chain payload rather than legitimate functionality. Concrete remote endpoints are hidden by string-array obfuscation and not recoverable from the provided data.
Potential Impact
This malicious code can execute arbitrary PowerShell commands on Windows hosts during package installation and runtime, potentially allowing attackers to perform host reconnaissance and exfiltrate identifying information to remote servers. This compromises the security and privacy of affected systems and may facilitate further attacks or persistence. The presence of obfuscated code and outbound beaconing indicates a supply-chain compromise with significant risk to users installing these package versions.
Mitigation Recommendations
No official patch or remediation information is provided. Users should immediately cease using the affected versions of trimprompt (1.0.35, 1.0.42, 1.0.46, 1.0.47, 1.0.48, 1.0.49). It is recommended to audit and remove these versions from environments and replace them with trusted alternatives or versions verified clean by the vendor or community. Monitor for unexpected PowerShell executions and network traffic to unknown endpoints on Windows hosts where these versions were installed. Check the vendor advisory for any updates on remediation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13462
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a7573b5bf8831d539d93b7c
Added to database: 08/07/2026, 05:57:09 UTC
Last enriched: 08/07/2026, 07:42:20 UTC
Last updated: 08/07/2026, 07:42:20 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.