Malicious code in ttspc-server-sample (npm)
The npm package 'ttspc-server-sample' versions 9.0.0, 9.0.1, 99.9.0, 99.9.1, 99.9.2, and 99.9.3 contains malicious code that executes automatically upon installation. It collects sensitive system information including hostname, username, environment variables resembling credentials, network interface details, OS information, and running processes, then exfiltrates this data to an attacker-controlled domain. The package uses an inflated version number to override private internal packages, enabling a supply-chain attack. Systems with this package installed should be considered fully compromised, and all secrets should be rotated. Removal of the package alone may not fully remediate the compromise.
AI Analysis
Technical Summary
The 'ttspc-server-sample' npm package at specified versions declares a postinstall script that runs 'index.js' automatically during installation. This script collects extensive host information such as hostname, username, current directory, network IPs and MAC addresses, OS details, environment variables including those resembling credentials, and a full process list. It then sends this data via HTTP POST to a hardcoded attacker-controlled Burp Collaborator endpoint. The package uses a high version number (99.9.x) to supersede legitimate private packages in victim organizations, constituting a dependency confusion supply-chain attack. The package is identified as malicious by multiple sources including Amazon Inspector, GHSA malware database, and OpenSSF Package Analysis. There is no CVSS score or known exploits in the wild reported. The attack compromises the host fully, requiring secret rotation and comprehensive remediation.
Potential Impact
Installation of this package results in immediate exfiltration of sensitive host information and environment variables that may contain credentials. The attacker gains knowledge of internal IP addresses, running processes, and potentially secret keys. The system is considered fully compromised, and secrets stored on the host should be rotated. Removal of the package does not guarantee full remediation due to possible further malicious persistence.
Mitigation Recommendations
No official patch or fix is available for this malicious package. The recommended mitigation is to immediately remove the package from any affected systems and consider those systems fully compromised. All secrets and keys stored on the compromised hosts should be rotated from a secure, unaffected environment. Vigilance against dependency confusion attacks is advised, including strict controls on package source resolution and verification of package provenance.
Malicious code in ttspc-server-sample (npm)
Description
The npm package 'ttspc-server-sample' versions 9.0.0, 9.0.1, 99.9.0, 99.9.1, 99.9.2, and 99.9.3 contains malicious code that executes automatically upon installation. It collects sensitive system information including hostname, username, environment variables resembling credentials, network interface details, OS information, and running processes, then exfiltrates this data to an attacker-controlled domain. The package uses an inflated version number to override private internal packages, enabling a supply-chain attack. Systems with this package installed should be considered fully compromised, and all secrets should be rotated. Removal of the package alone may not fully remediate the compromise.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'ttspc-server-sample' npm package at specified versions declares a postinstall script that runs 'index.js' automatically during installation. This script collects extensive host information such as hostname, username, current directory, network IPs and MAC addresses, OS details, environment variables including those resembling credentials, and a full process list. It then sends this data via HTTP POST to a hardcoded attacker-controlled Burp Collaborator endpoint. The package uses a high version number (99.9.x) to supersede legitimate private packages in victim organizations, constituting a dependency confusion supply-chain attack. The package is identified as malicious by multiple sources including Amazon Inspector, GHSA malware database, and OpenSSF Package Analysis. There is no CVSS score or known exploits in the wild reported. The attack compromises the host fully, requiring secret rotation and comprehensive remediation.
Potential Impact
Installation of this package results in immediate exfiltration of sensitive host information and environment variables that may contain credentials. The attacker gains knowledge of internal IP addresses, running processes, and potentially secret keys. The system is considered fully compromised, and secrets stored on the host should be rotated. Removal of the package does not guarantee full remediation due to possible further malicious persistence.
Mitigation Recommendations
No official patch or fix is available for this malicious package. The recommended mitigation is to immediately remove the package from any affected systems and consider those systems fully compromised. All secrets and keys stored on the compromised hosts should be rotated from a secure, unaffected environment. Vigilance against dependency confusion attacks is advised, including strict controls on package source resolution and verification of package provenance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-5707
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-55wh-p7q3-vh4p"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a4f6c3968715ace431588f4
Added to database: 07/09/2026, 09:39:05 UTC
Last enriched: 07/09/2026, 09:53:10 UTC
Last updated: 07/21/2026, 02:52:55 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.