Skip to main content

Malicious code in upshift-finance (npm)

0
Medium
Published: 08/11/2026 (08/11/2026, 00:00:00 UTC)
Source: GCVE Database
Product: upshift-finance

Description

The upshift-finance npm package version 1.0.0 is a malicious repack of the legitimate @augustdigital/sdk package. It includes a postinstall script that silently sends host-specific information such as hostname, username, and working directory to an attacker-controlled Cloudflare Workers endpoint. The malicious behavior is limited to this data exfiltration beacon, with no additional payload or credential theft observed. This package was published by an unrelated freemail account shortly after two similarly named packages, indicating a brand hijack attempt. Hosts that installed this package have had identifying information disclosed to the attacker.

Affected software

npmghsa
upshift-finance
Affected versions
=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 16:39:02 UTC

Technical Analysis

The upshift-finance npm package (version 1.0.0) is a renamed repack of the legitimate @augustdigital/sdk package, with an added unconditional postinstall hook. This hook executes a node script on installation that sends the installer's os.hostname(), os.userInfo().username, process.cwd(), package name, version, and timestamp via HTTPS GET to a Cloudflare Workers subdomain impersonating build/CDN health infrastructure. The endpoint is not disclosed in the package metadata, and there is no opt-out mechanism. The rest of the package code is identical to the legitimate SDK and contains no further malicious code. This behavior leaks host-identifying information to an attacker-controlled server.

Potential Impact

Hosts that install this malicious package leak their hostname, username, and current working directory path to an attacker-controlled endpoint. This disclosure of host-specific information can aid attackers in reconnaissance and further targeted attacks. No direct credential theft or secondary payload delivery has been observed. The malicious behavior occurs silently during npm install, potentially affecting any environment where this package is installed.

Mitigation Recommendations

No official patch or fix is available for this malicious package. The recommended mitigation is to avoid installing the upshift-finance package version 1.0.0 and instead use the legitimate @augustdigital/sdk package from its official source. Hosts that have installed the malicious package should consider the disclosed host information compromised and take appropriate internal security measures. Monitor for and remove any instances of the upshift-finance package from your environments.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13777
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6a7c9b44bf8831d539cdcf89

Added to database: 08/12/2026, 16:11:48 UTC

Last enriched: 08/12/2026, 16:39:02 UTC

Last updated: 09/25/2026, 09:32:25 UTC

Views: 21

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses