Malicious code in yangming708 (npm)
The npm package 'yangming708' version 1.0.0 contains a tarball with only a package.json and an index.html file. The package.json specifies 'index.html' as the main entry, which is not a Node.js module, and no lifecycle scripts are declared. The index.html includes an obfuscated script that, when opened in a browser, redirects to a potentially malicious URL. Installing or requiring the package in a Node.js environment does not execute this code. However, if the HTML is opened in a browser, it can lead to a redirect to a malicious site. The package appears to be registry spam or a mispublished browser-side redirect page rather than a direct supply-chain attack. Despite this, one source claims that any system with this package installed or running should be considered compromised, recommending immediate secret rotation and package removal.
AI Analysis
Technical Summary
The 'yangming708' npm package version 1.0.0 contains no executable Node.js code but includes an index.html file with an obfuscated script that performs a browser redirect to an encoded URL. Since npm install does not execute HTML and the main file is not a Node module, the malicious code does not run during installation or require/import in Node.js environments. This suggests the package is registry spam or a browser-side redirect page mistakenly published as an npm package. However, a security source warns that any computer with this package installed or running should be considered fully compromised, recommending removal and secret rotation, though no direct evidence of code execution on install is described.
Potential Impact
Installing or loading the package in a Node.js environment does not execute malicious code, so there is no direct impact on developer or build machines from npm install or require/import. However, if the index.html file is opened in a browser, the obfuscated script executes and redirects to a potentially malicious URL, which could lead to further compromise. One source claims that systems with this package installed or running are fully compromised, implying possible post-installation exploitation or secondary payloads, though these are not detailed in the provided data.
Mitigation Recommendations
Since the package does not execute code during npm install or require/import, no immediate action is required for typical Node.js usage. However, users should avoid opening the index.html file in a browser. The package should be removed from any systems where it is installed. If the package was executed or the index.html opened in a browser, it is recommended to consider the system compromised, rotate all secrets and keys from a different machine, and perform a thorough security assessment. Patch status is not applicable as this is a malicious package rather than a vulnerability with a fix.
Malicious code in yangming708 (npm)
Description
The npm package 'yangming708' version 1.0.0 contains a tarball with only a package.json and an index.html file. The package.json specifies 'index.html' as the main entry, which is not a Node.js module, and no lifecycle scripts are declared. The index.html includes an obfuscated script that, when opened in a browser, redirects to a potentially malicious URL. Installing or requiring the package in a Node.js environment does not execute this code. However, if the HTML is opened in a browser, it can lead to a redirect to a malicious site. The package appears to be registry spam or a mispublished browser-side redirect page rather than a direct supply-chain attack. Despite this, one source claims that any system with this package installed or running should be considered compromised, recommending immediate secret rotation and package removal.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'yangming708' npm package version 1.0.0 contains no executable Node.js code but includes an index.html file with an obfuscated script that performs a browser redirect to an encoded URL. Since npm install does not execute HTML and the main file is not a Node module, the malicious code does not run during installation or require/import in Node.js environments. This suggests the package is registry spam or a browser-side redirect page mistakenly published as an npm package. However, a security source warns that any computer with this package installed or running should be considered fully compromised, recommending removal and secret rotation, though no direct evidence of code execution on install is described.
Potential Impact
Installing or loading the package in a Node.js environment does not execute malicious code, so there is no direct impact on developer or build machines from npm install or require/import. However, if the index.html file is opened in a browser, the obfuscated script executes and redirects to a potentially malicious URL, which could lead to further compromise. One source claims that systems with this package installed or running are fully compromised, implying possible post-installation exploitation or secondary payloads, though these are not detailed in the provided data.
Mitigation Recommendations
Since the package does not execute code during npm install or require/import, no immediate action is required for typical Node.js usage. However, users should avoid opening the index.html file in a browser. The package should be removed from any systems where it is installed. If the package was executed or the index.html opened in a browser, it is recommended to consider the system compromised, rotate all secrets and keys from a different machine, and perform a thorough security assessment. Patch status is not applicable as this is a malicious package rather than a vulnerability with a fix.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13845
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-vgr6-626m-8w22"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a7c9b43bf8831d539cdcf20
Added to database: 08/12/2026, 16:11:47 UTC
Last enriched: 08/12/2026, 16:37:20 UTC
Last updated: 08/12/2026, 16:37:20 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.