Malicious code in whs4_ued (npm)
The npm package whs4_ued version 1.0.0 contains malicious code that executes during installation. Its postinstall script runs a Node.js script that sends sensitive host information, including the absolute path of the package file (revealing OS username and home directory structure), Node.js version, platform, and architecture, to an attacker-controlled Discord webhook without user consent.
AI Analysis
Technical Summary
The whs4_ued npm package version 1.0.0 includes a postinstall hook that executes 'node index.js'. This script collects installer host details such as the absolute package file path, Node.js version, platform, and architecture, then transmits this data to a hardcoded Discord webhook URL. The webhook token is obfuscated via string concatenation to evade simple detection. The destination is attacker-controlled and unrelated to the package's stated purpose, indicating malicious intent and unauthorized data exfiltration.
Potential Impact
This behavior results in leakage of potentially sensitive environment information including the OS username and home directory layout, which could aid attackers in further reconnaissance or targeted attacks. The data exfiltration occurs silently during installation without user consent, violating privacy and security expectations.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid installing version 1.0.0 of the whs4_ued package. Verify package integrity and source before installation. Monitor for updates or advisories from the package maintainer or npm registry regarding remediation.
Malicious code in whs4_ued (npm)
Description
The npm package whs4_ued version 1.0.0 contains malicious code that executes during installation. Its postinstall script runs a Node.js script that sends sensitive host information, including the absolute path of the package file (revealing OS username and home directory structure), Node.js version, platform, and architecture, to an attacker-controlled Discord webhook without user consent.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The whs4_ued npm package version 1.0.0 includes a postinstall hook that executes 'node index.js'. This script collects installer host details such as the absolute package file path, Node.js version, platform, and architecture, then transmits this data to a hardcoded Discord webhook URL. The webhook token is obfuscated via string concatenation to evade simple detection. The destination is attacker-controlled and unrelated to the package's stated purpose, indicating malicious intent and unauthorized data exfiltration.
Potential Impact
This behavior results in leakage of potentially sensitive environment information including the OS username and home directory layout, which could aid attackers in further reconnaissance or targeted attacks. The data exfiltration occurs silently during installation without user consent, violating privacy and security expectations.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid installing version 1.0.0 of the whs4_ued package. Verify package integrity and source before installation. Monitor for updates or advisories from the package maintainer or npm registry regarding remediation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13743
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a7b6fbcbf8831d5393e7b10
Added to database: 08/11/2026, 18:53:48 UTC
Last enriched: 08/11/2026, 18:56:17 UTC
Last updated: 08/11/2026, 18:58:45 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.