Skip to main content

Malicious code in velabuild (npm)

0
Critical
Published: 08/07/2026 (08/07/2026, 00:06:23 UTC)
Source: GCVE Database
Product: velabuild

Description

The velabuild npm package contains embedded malicious code that includes a base64-encoded RSA private key used to establish SSH connections to an attacker's server. This private key is identical for every installer, granting anyone who installs the package valid SSH credentials to the attacker's server. While the package does not execute attacker-controlled code during installation or modify the installer's filesystem beyond a temporary key file, it enables remote command execution via SSH when specific subcommands are invoked. The package's signup and login commands transmit user credentials over this SSH tunnel. Systems with this package installed should be considered fully compromised.

Affected software

npmghsa
velabuild
Affected versions
=2.1.1=1.0.1=2.0.0=1.0.0=1.0.3=1.0.2=2.2.0=2.1.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/07/2026, 15:41:31 UTC

Technical Analysis

The velabuild npm package versions 1.0.0, 1.0.1, 1.0.2, 1.0.3, 2.0.0, 2.1.0, 2.1.1, and 2.2.0 embed a base64-encoded RSA private key within the CLI code. This key is decoded to a temporary file with restricted permissions and used to SSH into a remote server controlled by the attacker. This SSH access allows execution of bash scripts on the attacker's server related to signup, login, and deploy commands. The private key is shipped identically to all users, meaning any installer gains unauthorized access to the attacker's server. The package does not fetch or execute remote code during installation but enables remote command execution when certain subcommands are explicitly run by the user. The signup and login subcommands pass user credentials as shell arguments over the SSH tunnel. Due to this, any system with this package installed should be treated as fully compromised.

Potential Impact

Systems with the affected velabuild package installed are fully compromised because the embedded private key grants unauthorized SSH access to the attacker's server. This access can lead to remote command execution and potential data exfiltration or further compromise. User credentials passed during signup/login commands are exposed over the SSH tunnel. The compromise extends beyond the package itself, as the attacker may have established persistent control over the system.

Mitigation Recommendations

No official patch or fix is currently documented. Immediate removal of the velabuild package is recommended. All secrets and keys on affected systems should be rotated from a separate, trusted machine. Given the full compromise risk, affected systems should be considered untrusted and undergo thorough incident response procedures. Monitor for any unauthorized access or persistence mechanisms. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13493
Osv Schema Version
1.7.4
Aliases
["GHSA-q7w3-723m-252j"]
Ecosystems
["npm"]

Threat ID: 6a75f711bf8831d53984fb5d

Added to database: 08/07/2026, 15:17:37 UTC

Last enriched: 08/07/2026, 15:41:31 UTC

Last updated: 09/21/2026, 23:46:20 UTC

Views: 28

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses