Recovering a removed npm malware file using Software Heritage and a surviving CDN digest
Description
This report details the recovery of a removed npm malware file from the scoped package @goodjavascript/[email protected] using archival sources and CDN metadata. The recovered file contained a timer-based mechanism that collects host information and can execute JavaScript from a server response. The package itself had no installation scripts and an empty exported config function. The recovery was achieved by correlating an older Software Heritage snapshot with a surviving SHA-256 digest from jsDelivr's file manifest. A Python verifier was developed to safely retrieve and hash the file without execution. This analysis supplements an existing OSV advisory and highlights the use of archival tools for malware investigation.
Reddit Discussion
I wrote up my investigation into @goodjavascript/[email protected], including how to recover its entry-point file after the npm tarball and jsDelivr file URLs returned 404.
The useful detail: Software Heritage’s latest snapshot contained only the security placeholder. An older snapshot retained the original release and its 840-byte index.js. Its SHA-256 matched the digest still available in jsDelivr’s file manifest.
Static inspection showed a timer scheduled at module load that collects host information and can execute JavaScript supplied in a server response. The package had no installation scripts, and its exported config() function was empty.
The article includes the package-to-archive discovery steps, dated evidence, an annotated code excerpt and a Python verifier that retrieves and hashes the file without executing it. It also links my analysis contribution to the existing OSV advisory.
https://cgsec.dev/research/dotenv-recovery/
This concerns the scoped @goodjavascript/dotenv package, not the unscoped dotenv package.
Have you used other archives or retained metadata sources to recover removed package evidence?
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The investigation focused on the scoped npm package @goodjavascript/[email protected], whose malware-laden entry-point file was removed from npm and jsDelivr CDN, returning 404 errors. Using Software Heritage archival snapshots, an older version of the package containing the original 840-byte index.js file was found. The SHA-256 hash of this file matched a digest still listed in jsDelivr's file manifest, confirming its authenticity. Static code analysis revealed a timer that collects host information and executes JavaScript supplied by a remote server, indicating malicious behavior. The package lacked installation scripts and had an empty exported config function, suggesting the malicious payload was triggered at runtime. The researcher provided detailed recovery steps, dated evidence, annotated code excerpts, and a Python script to verify the file's integrity without executing it. This work contributes to the existing OSV advisory on this malware.
Potential Impact
The malicious package could collect host information and execute arbitrary JavaScript code supplied by a remote server, potentially enabling remote code execution or data exfiltration on affected systems. Since the package was removed from npm and CDN sources, the risk of new infections is reduced, but systems that previously installed the package may remain compromised if not remediated. No active exploits in the wild are reported. The malware's stealthy design (no install scripts, empty exported function) could have delayed detection.
Defensive Guidance
The malicious package @goodjavascript/[email protected] has been removed from npm and CDN sources, reducing exposure. Users should verify their dependencies to ensure this package is not present. Since the package is removed, no direct patch exists. The recovery and analysis provided can assist in forensic investigations. No additional vendor advisories or patches are indicated. Users should rely on existing OSV advisories and remove any instances of the malicious package from their environments.
Technical Details
- Source Type
- Subreddit
- Malware
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":38,"reasons":["external_link","newsworthy_keywords:malware","established_author","recent_news"],"isNewsworthy":true,"foundNewsworthy":["malware"]}
- Has External Source
- false
- Trusted Domain
- false
Threat ID: 6ac384002cdf04f656f4e3c3
Added to database: 10/05/2026, 11:03:28 UTC
Last enriched: 10/05/2026, 11:03:33 UTC
Last updated: 10/05/2026, 19:48:16 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.