Malicious code in zeal-rq-hooks (npm)
The npm package zeal-rq-hooks version 0.0.0 contains embedded malicious code in canary.js that collects host-identifying information such as hostname, username, platform, Node/npm version, and current working directory. This data is sent via a POST request to a hardcoded external endpoint not affiliated with the npm registry or the package publisher. This behavior constitutes a privacy and security risk due to unauthorized data exfiltration.
AI Analysis
Technical Summary
The zeal-rq-hooks npm package (version 0.0.0) includes a file named canary.js which imports core Node.js modules (os, http, https) and at a specific code location (line 123) sends a JSON payload containing sensitive host information (os.hostname(), os.userInfo(), process.platform, Node/npm version, and cwd) to a hardcoded URL (https://npm-canary.aveliscare.com). The endpoint is not user-configurable and is unrelated to the official npm registry or the package publisher, indicating malicious intent for reconnaissance or data exfiltration.
Potential Impact
The malicious code collects and transmits host-identifying reconnaissance data without user consent, potentially exposing sensitive environment details to an unknown third party. This can lead to privacy violations and may facilitate further targeted attacks if the data is used maliciously. No direct evidence of exploitation in the wild is reported.
Mitigation Recommendations
No official patch or remediation guidance is provided. Users should avoid installing or using the zeal-rq-hooks package version 0.0.0. Review and remove any installations of this package from projects and dependency trees. Monitor for updates or advisories from trusted sources regarding this package.
Malicious code in zeal-rq-hooks (npm)
Description
The npm package zeal-rq-hooks version 0.0.0 contains embedded malicious code in canary.js that collects host-identifying information such as hostname, username, platform, Node/npm version, and current working directory. This data is sent via a POST request to a hardcoded external endpoint not affiliated with the npm registry or the package publisher. This behavior constitutes a privacy and security risk due to unauthorized data exfiltration.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The zeal-rq-hooks npm package (version 0.0.0) includes a file named canary.js which imports core Node.js modules (os, http, https) and at a specific code location (line 123) sends a JSON payload containing sensitive host information (os.hostname(), os.userInfo(), process.platform, Node/npm version, and cwd) to a hardcoded URL (https://npm-canary.aveliscare.com). The endpoint is not user-configurable and is unrelated to the official npm registry or the package publisher, indicating malicious intent for reconnaissance or data exfiltration.
Potential Impact
The malicious code collects and transmits host-identifying reconnaissance data without user consent, potentially exposing sensitive environment details to an unknown third party. This can lead to privacy violations and may facilitate further targeted attacks if the data is used maliciously. No direct evidence of exploitation in the wild is reported.
Mitigation Recommendations
No official patch or remediation guidance is provided. Users should avoid installing or using the zeal-rq-hooks package version 0.0.0. Review and remove any installations of this package from projects and dependency trees. Monitor for updates or advisories from trusted sources regarding this package.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13742
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a7b6fbcbf8831d5393e7b13
Added to database: 08/11/2026, 18:53:48 UTC
Last enriched: 08/11/2026, 18:56:27 UTC
Last updated: 08/11/2026, 18:56:27 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.