Malicious code in upshift-finance (npm)
The upshift-finance npm package version 1.0.0 is a malicious repack of the legitimate @augustdigital/sdk package. It includes a postinstall script that silently sends host-specific information such as hostname, username, and working directory to an attacker-controlled Cloudflare Workers endpoint. The malicious behavior is limited to this data exfiltration beacon, with no additional payload or credential theft observed. This package was published by an unrelated freemail account shortly after two similarly named packages, indicating a brand hijack attempt. Hosts that installed this package have had identifying information disclosed to the attacker.
AI Analysis
Technical Summary
The upshift-finance npm package (version 1.0.0) is a renamed repack of the legitimate @augustdigital/sdk package, with an added unconditional postinstall hook. This hook executes a node script on installation that sends the installer's os.hostname(), os.userInfo().username, process.cwd(), package name, version, and timestamp via HTTPS GET to a Cloudflare Workers subdomain impersonating build/CDN health infrastructure. The endpoint is not disclosed in the package metadata, and there is no opt-out mechanism. The rest of the package code is identical to the legitimate SDK and contains no further malicious code. This behavior leaks host-identifying information to an attacker-controlled server.
Potential Impact
Hosts that install this malicious package leak their hostname, username, and current working directory path to an attacker-controlled endpoint. This disclosure of host-specific information can aid attackers in reconnaissance and further targeted attacks. No direct credential theft or secondary payload delivery has been observed. The malicious behavior occurs silently during npm install, potentially affecting any environment where this package is installed.
Mitigation Recommendations
No official patch or fix is available for this malicious package. The recommended mitigation is to avoid installing the upshift-finance package version 1.0.0 and instead use the legitimate @augustdigital/sdk package from its official source. Hosts that have installed the malicious package should consider the disclosed host information compromised and take appropriate internal security measures. Monitor for and remove any instances of the upshift-finance package from your environments.
Malicious code in upshift-finance (npm)
Description
The upshift-finance npm package version 1.0.0 is a malicious repack of the legitimate @augustdigital/sdk package. It includes a postinstall script that silently sends host-specific information such as hostname, username, and working directory to an attacker-controlled Cloudflare Workers endpoint. The malicious behavior is limited to this data exfiltration beacon, with no additional payload or credential theft observed. This package was published by an unrelated freemail account shortly after two similarly named packages, indicating a brand hijack attempt. Hosts that installed this package have had identifying information disclosed to the attacker.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The upshift-finance npm package (version 1.0.0) is a renamed repack of the legitimate @augustdigital/sdk package, with an added unconditional postinstall hook. This hook executes a node script on installation that sends the installer's os.hostname(), os.userInfo().username, process.cwd(), package name, version, and timestamp via HTTPS GET to a Cloudflare Workers subdomain impersonating build/CDN health infrastructure. The endpoint is not disclosed in the package metadata, and there is no opt-out mechanism. The rest of the package code is identical to the legitimate SDK and contains no further malicious code. This behavior leaks host-identifying information to an attacker-controlled server.
Potential Impact
Hosts that install this malicious package leak their hostname, username, and current working directory path to an attacker-controlled endpoint. This disclosure of host-specific information can aid attackers in reconnaissance and further targeted attacks. No direct credential theft or secondary payload delivery has been observed. The malicious behavior occurs silently during npm install, potentially affecting any environment where this package is installed.
Mitigation Recommendations
No official patch or fix is available for this malicious package. The recommended mitigation is to avoid installing the upshift-finance package version 1.0.0 and instead use the legitimate @augustdigital/sdk package from its official source. Hosts that have installed the malicious package should consider the disclosed host information compromised and take appropriate internal security measures. Monitor for and remove any instances of the upshift-finance package from your environments.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13777
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a7c9b44bf8831d539cdcf89
Added to database: 08/12/2026, 16:11:48 UTC
Last enriched: 08/12/2026, 16:39:02 UTC
Last updated: 09/25/2026, 09:32:25 UTC
Views: 21
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.