Malicious code in weavedb-client (npm)
The weavedb-client npm package version 0.45.3 contains a malicious preinstall script that executes a UPX-packed Linux ELF binary during installation. This binary acts as an infostealer targeting developer credentials such as SSH/PuTTY private keys, GitHub tokens, OAuth/Discord tokens, and environment variables. It also injects malicious code into the Exodus cryptocurrency wallet to capture sensitive data and uses worm-like behavior to propagate by stealing GitHub and npm credentials. The malware employs an eBPF-based kernel rootkit on Linux to hide its presence. Installation of this package version can lead to full system compromise.
AI Analysis
Technical Summary
The weavedb-client npm package version 0.45.3 was compromised as part of the IronWorm campaign. It includes a preinstall hook that executes a large UPX-packed Linux x86-64 ELF binary, which is a Rust-built infostealer. This binary harvests a wide range of developer credentials including SSH/PuTTY private keys, GitHub and OAuth tokens, environment variables, and cryptocurrency wallet secrets by injecting malicious JavaScript into the Exodus wallet. The malware exhibits worm-like propagation by stealing credentials to push malicious updates and publish trojanized packages. Additionally, it uses an eBPF-based kernel rootkit to hide its processes and network activity on Linux systems. The presence of this package on a system indicates a high likelihood of full compromise.
Potential Impact
Installation of the affected package version results in execution of a malicious native binary that steals sensitive credentials and tokens related to developer environments, cloud providers, source control, package registries, and cryptocurrency wallets. The malware can fully compromise the infected system, enabling attackers to exfiltrate secrets and potentially maintain persistent, hidden access via a kernel rootkit. The worm-like behavior allows attackers to spread by abusing stolen credentials to compromise additional repositories and publish further malicious packages.
Mitigation Recommendations
No official patch or fix is currently available for this malicious package version. The vendor advisory is not provided, but the threat intelligence sources recommend immediate removal of the package. Systems with this package installed should be considered fully compromised; all secrets and keys must be rotated from a separate, trusted machine. Because the malware includes a kernel rootkit and extensive credential theft, full system reimaging is strongly advised to ensure complete eradication. Avoid installing this package version and verify package integrity before installation in the future.
Malicious code in weavedb-client (npm)
Description
The weavedb-client npm package version 0.45.3 contains a malicious preinstall script that executes a UPX-packed Linux ELF binary during installation. This binary acts as an infostealer targeting developer credentials such as SSH/PuTTY private keys, GitHub tokens, OAuth/Discord tokens, and environment variables. It also injects malicious code into the Exodus cryptocurrency wallet to capture sensitive data and uses worm-like behavior to propagate by stealing GitHub and npm credentials. The malware employs an eBPF-based kernel rootkit on Linux to hide its presence. Installation of this package version can lead to full system compromise.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The weavedb-client npm package version 0.45.3 was compromised as part of the IronWorm campaign. It includes a preinstall hook that executes a large UPX-packed Linux x86-64 ELF binary, which is a Rust-built infostealer. This binary harvests a wide range of developer credentials including SSH/PuTTY private keys, GitHub and OAuth tokens, environment variables, and cryptocurrency wallet secrets by injecting malicious JavaScript into the Exodus wallet. The malware exhibits worm-like propagation by stealing credentials to push malicious updates and publish trojanized packages. Additionally, it uses an eBPF-based kernel rootkit to hide its processes and network activity on Linux systems. The presence of this package on a system indicates a high likelihood of full compromise.
Potential Impact
Installation of the affected package version results in execution of a malicious native binary that steals sensitive credentials and tokens related to developer environments, cloud providers, source control, package registries, and cryptocurrency wallets. The malware can fully compromise the infected system, enabling attackers to exfiltrate secrets and potentially maintain persistent, hidden access via a kernel rootkit. The worm-like behavior allows attackers to spread by abusing stolen credentials to compromise additional repositories and publish further malicious packages.
Mitigation Recommendations
No official patch or fix is currently available for this malicious package version. The vendor advisory is not provided, but the threat intelligence sources recommend immediate removal of the package. Systems with this package installed should be considered fully compromised; all secrets and keys must be rotated from a separate, trusted machine. Because the malware includes a kernel rootkit and extensive credential theft, full system reimaging is strongly advised to ensure complete eradication. Avoid installing this package version and verify package integrity before installation in the future.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-4716
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-6fj3-894w-h3x9"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a55ff7168715ace432f22fa
Added to database: 07/14/2026, 09:20:49 UTC
Last enriched: 07/14/2026, 09:36:55 UTC
Last updated: 07/27/2026, 03:38:55 UTC
Views: 16
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.