Malicious code in uncaxss (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (acda9720ae54881219c0fbcee73795be85877d292aa62662f7cb6b92e775f608) Package ships an obfuscated dist/index.js that is invoked from the postinstall lifecycle hook (`node dist/index.js`). At install time, the script performs an HTTPS GET to https://onch.cc/test1.txt (and https://onch.cc/test2.txt), base64-decodes the response body, and executes it via `new Function('require', decoded)()`, granting the fetched code full Node.js capabilities (including `require`) on the installer's machine. The dropper is gated by `process.env.P == 1`, allowing the attacker to keep the payload dormant on incidental installers and detonate selectively (e.g., on CI runners where P is set). The fetching logic is obfuscated using javascript-obfuscator (hex identifiers, rotating string array, decoder wrapper), and the package's own build script (`"obfuscate": "javascript-obfuscator./dist/index.js..."`) confirms obfuscation is applied deliberately before publish. The remote host onch.cc is unrelated to any documented package purpose (the package has no README), and the fetched content is opaque, mutable, and unpinned. This is a classic install-time RCE dropper with attacker-controlled remote code execution on `npm install`.
AI Analysis
Technical Summary
The uncaxss npm package versions 1.3.4 and 1.3.5 include an obfuscated postinstall script that performs an HTTPS GET request to attacker-controlled URLs, retrieves base64-encoded JavaScript, and executes it dynamically using new Function with full Node.js capabilities. This results in remote code execution on the installer's system at install time. The payload activation is gated by the environment variable process.env.P set to 1, enabling selective execution, such as targeting CI environments. The obfuscation and lack of legitimate package documentation confirm malicious intent. No patch or remediation is currently documented.
Potential Impact
Installing affected versions of the uncaxss package results in remote code execution on the installing system with full Node.js privileges. This can lead to arbitrary code execution, potential system compromise, data theft, or further malware deployment. The selective activation mechanism allows attackers to evade detection by only triggering on specific environments.
Mitigation Recommendations
No official patch or remediation is currently available. Users should avoid installing versions 1.3.4 and 1.3.5 of the uncaxss package. Audit dependencies for this package and remove or replace it if found. Monitor for any updates from the package maintainer or npm advisories for remediation guidance.
Malicious code in uncaxss (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (acda9720ae54881219c0fbcee73795be85877d292aa62662f7cb6b92e775f608) Package ships an obfuscated dist/index.js that is invoked from the postinstall lifecycle hook (`node dist/index.js`). At install time, the script performs an HTTPS GET to https://onch.cc/test1.txt (and https://onch.cc/test2.txt), base64-decodes the response body, and executes it via `new Function('require', decoded)()`, granting the fetched code full Node.js capabilities (including `require`) on the installer's machine. The dropper is gated by `process.env.P == 1`, allowing the attacker to keep the payload dormant on incidental installers and detonate selectively (e.g., on CI runners where P is set). The fetching logic is obfuscated using javascript-obfuscator (hex identifiers, rotating string array, decoder wrapper), and the package's own build script (`"obfuscate": "javascript-obfuscator./dist/index.js..."`) confirms obfuscation is applied deliberately before publish. The remote host onch.cc is unrelated to any documented package purpose (the package has no README), and the fetched content is opaque, mutable, and unpinned. This is a classic install-time RCE dropper with attacker-controlled remote code execution on `npm install`.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The uncaxss npm package versions 1.3.4 and 1.3.5 include an obfuscated postinstall script that performs an HTTPS GET request to attacker-controlled URLs, retrieves base64-encoded JavaScript, and executes it dynamically using new Function with full Node.js capabilities. This results in remote code execution on the installer's system at install time. The payload activation is gated by the environment variable process.env.P set to 1, enabling selective execution, such as targeting CI environments. The obfuscation and lack of legitimate package documentation confirm malicious intent. No patch or remediation is currently documented.
Potential Impact
Installing affected versions of the uncaxss package results in remote code execution on the installing system with full Node.js privileges. This can lead to arbitrary code execution, potential system compromise, data theft, or further malware deployment. The selective activation mechanism allows attackers to evade detection by only triggering on specific environments.
Mitigation Recommendations
No official patch or remediation is currently available. Users should avoid installing versions 1.3.4 and 1.3.5 of the uncaxss package. Audit dependencies for this package and remove or replace it if found. Monitor for any updates from the package maintainer or npm advisories for remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10176
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a520eaf68715ace438f4c93
Added to database: 07/11/2026, 09:36:47 UTC
Last enriched: 07/11/2026, 09:47:41 UTC
Last updated: 07/30/2026, 01:44:16 UTC
Views: 27
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.