Skip to main content

Recovering a removed npm malware file using Software Heritage and a surviving CDN digest

0
Medium
Published: 10/05/2026 (10/05/2026, 05:50:53 UTC)
Source: Reddit Malware

Description

This report details the recovery of a removed npm malware file from the scoped package @goodjavascript/[email protected] using archival sources and CDN metadata. The recovered file contained a timer-based mechanism that collects host information and can execute JavaScript from a server response. The package itself had no installation scripts and an empty exported config function. The recovery was achieved by correlating an older Software Heritage snapshot with a surviving SHA-256 digest from jsDelivr's file manifest. A Python verifier was developed to safely retrieve and hash the file without execution. This analysis supplements an existing OSV advisory and highlights the use of archival tools for malware investigation.

Reddit Discussion

r/Malware·posted by u/APT-vs-BellyFAT
00

I wrote up my investigation into @goodjavascript/[email protected], including how to recover its entry-point file after the npm tarball and jsDelivr file URLs returned 404.
The useful detail: Software Heritage’s latest snapshot contained only the security placeholder. An older snapshot retained the original release and its 840-byte index.js. Its SHA-256 matched the digest still available in jsDelivr’s file manifest.
Static inspection showed a timer scheduled at module load that collects host information and can execute JavaScript supplied in a server response. The package had no installation scripts, and its exported config() function was empty.
The article includes the package-to-archive discovery steps, dated evidence, an annotated code excerpt and a Python verifier that retrieves and hashes the file without executing it. It also links my analysis contribution to the existing OSV advisory.
https://cgsec.dev/research/dotenv-recovery/
This concerns the scoped @goodjavascript/dotenv package, not the unscoped dotenv package.
Have you used other archives or retained metadata sources to recover removed package evidence?

Links cited in this discussion

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/05/2026, 11:03:33 UTC

Technical Analysis

The investigation focused on the scoped npm package @goodjavascript/[email protected], whose malware-laden entry-point file was removed from npm and jsDelivr CDN, returning 404 errors. Using Software Heritage archival snapshots, an older version of the package containing the original 840-byte index.js file was found. The SHA-256 hash of this file matched a digest still listed in jsDelivr's file manifest, confirming its authenticity. Static code analysis revealed a timer that collects host information and executes JavaScript supplied by a remote server, indicating malicious behavior. The package lacked installation scripts and had an empty exported config function, suggesting the malicious payload was triggered at runtime. The researcher provided detailed recovery steps, dated evidence, annotated code excerpts, and a Python script to verify the file's integrity without executing it. This work contributes to the existing OSV advisory on this malware.

Potential Impact

The malicious package could collect host information and execute arbitrary JavaScript code supplied by a remote server, potentially enabling remote code execution or data exfiltration on affected systems. Since the package was removed from npm and CDN sources, the risk of new infections is reduced, but systems that previously installed the package may remain compromised if not remediated. No active exploits in the wild are reported. The malware's stealthy design (no install scripts, empty exported function) could have delayed detection.

Defensive Guidance

The malicious package @goodjavascript/[email protected] has been removed from npm and CDN sources, reducing exposure. Users should verify their dependencies to ensure this package is not present. Since the package is removed, no direct patch exists. The recovery and analysis provided can assist in forensic investigations. No additional vendor advisories or patches are indicated. Users should rely on existing OSV advisories and remove any instances of the malicious package from their environments.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
Malware
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":38,"reasons":["external_link","newsworthy_keywords:malware","established_author","recent_news"],"isNewsworthy":true,"foundNewsworthy":["malware"]}
Has External Source
false
Trusted Domain
false

Threat ID: 6ac384002cdf04f656f4e3c3

Added to database: 10/05/2026, 11:03:28 UTC

Last enriched: 10/05/2026, 11:03:33 UTC

Last updated: 10/05/2026, 19:48:16 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses