Malicious code in weavedb-node-client (npm)
The weavedb-node-client npm package version 0.45.3 contains a malicious preinstall script that executes a packed native Linux binary. This binary acts as an infostealer targeting developer environments, harvesting credentials for cloud providers, source control, package registries, and cryptocurrency wallets. It also uses kernel-level rootkit techniques to hide its presence and exhibits worm-like behavior by stealing GitHub and npm credentials to propagate further malicious packages. Any system running npm install for this package on Linux is at risk of full compromise.
AI Analysis
Technical Summary
The weavedb-node-client package version 0.45.3 includes a preinstall lifecycle script that unconditionally executes a 976KB UPX-packed Linux x86 ELF binary with no source code or documented native dependencies. Analysis reveals this binary is a Rust-built infostealer that collects sensitive credentials related to cloud services, databases, source control, package registries, AI tools, and cryptocurrency wallets. It injects malicious JavaScript into the Exodus wallet to capture secrets and uses eBPF and ptrace primitives to perform kernel rootkit functions, hiding its processes and network activity. The malware also steals GitHub and npm credentials to push malicious updates and publish trojanized packages, enabling worm-like propagation. This threat is part of the IronWorm campaign and results in full system compromise when the package is installed on Linux systems.
Potential Impact
Systems installing weavedb-node-client version 0.45.3 on Linux execute attacker-controlled native code with user privileges, leading to full compromise. The malware steals a wide range of sensitive credentials including cloud provider tokens, source control keys, package registry credentials, and cryptocurrency wallet secrets. It also uses kernel rootkit techniques to evade detection and can propagate by pushing malicious updates to victim repositories and publishing trojanized npm packages. The compromise affects developer environments and continuous integration systems, potentially exposing all stored secrets and keys.
Mitigation Recommendations
No official patch or fix is currently available for this malicious package version. Users should immediately remove weavedb-node-client version 0.45.3 from their environments. All secrets and credentials stored on affected systems should be considered compromised and rotated from a secure, unaffected device. Due to the rootkit and worm-like behavior, full system reimaging or forensic analysis is recommended to ensure removal of all malicious components. Avoid installing this package version and monitor for any trojanized packages published by the attacker.
Malicious code in weavedb-node-client (npm)
Description
The weavedb-node-client npm package version 0.45.3 contains a malicious preinstall script that executes a packed native Linux binary. This binary acts as an infostealer targeting developer environments, harvesting credentials for cloud providers, source control, package registries, and cryptocurrency wallets. It also uses kernel-level rootkit techniques to hide its presence and exhibits worm-like behavior by stealing GitHub and npm credentials to propagate further malicious packages. Any system running npm install for this package on Linux is at risk of full compromise.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The weavedb-node-client package version 0.45.3 includes a preinstall lifecycle script that unconditionally executes a 976KB UPX-packed Linux x86 ELF binary with no source code or documented native dependencies. Analysis reveals this binary is a Rust-built infostealer that collects sensitive credentials related to cloud services, databases, source control, package registries, AI tools, and cryptocurrency wallets. It injects malicious JavaScript into the Exodus wallet to capture secrets and uses eBPF and ptrace primitives to perform kernel rootkit functions, hiding its processes and network activity. The malware also steals GitHub and npm credentials to push malicious updates and publish trojanized packages, enabling worm-like propagation. This threat is part of the IronWorm campaign and results in full system compromise when the package is installed on Linux systems.
Potential Impact
Systems installing weavedb-node-client version 0.45.3 on Linux execute attacker-controlled native code with user privileges, leading to full compromise. The malware steals a wide range of sensitive credentials including cloud provider tokens, source control keys, package registry credentials, and cryptocurrency wallet secrets. It also uses kernel rootkit techniques to evade detection and can propagate by pushing malicious updates to victim repositories and publishing trojanized npm packages. The compromise affects developer environments and continuous integration systems, potentially exposing all stored secrets and keys.
Mitigation Recommendations
No official patch or fix is currently available for this malicious package version. Users should immediately remove weavedb-node-client version 0.45.3 from their environments. All secrets and credentials stored on affected systems should be considered compromised and rotated from a secure, unaffected device. Due to the rootkit and worm-like behavior, full system reimaging or forensic analysis is recommended to ensure removal of all malicious components. Avoid installing this package version and monitor for any trojanized packages published by the attacker.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-4721
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-94x8-wq6v-6gwp"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a55ff7168715ace432f22f4
Added to database: 07/14/2026, 09:20:49 UTC
Last enriched: 07/14/2026, 09:36:44 UTC
Last updated: 07/28/2026, 09:39:51 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.