Threats Tagged 'mal-2026-6848'
View all threats tagged with 'mal-2026-6848'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'mal-2026-6848'
Click on any threat for detailed analysis and mitigation recommendations
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (6e034e855661cc792a14908c613b0d3ae31917a99927ddf0db29b1ae173df0cd) Package advertises itself as a log formatter but exposes an undocumented `threadContent` option on `createLogger()` that is forwarded to a worker thread which compiles and executes it via `new Function('require', payload)(require)` (src/worker.js lines 5-7, triggered from src/index.js lines 148-151). The eval only runs against a payload the caller explicitly supplies, so installing or requiring the package does not by itself execute attacker-controlled code, and there are no install hooks, no remote fetches, no credential reads, and no outbound exfiltration. However, the feature is undocumented in the README, is shaped like a backdoor primitive rather than logging functionality, and the package also pulls in `axios` and `request` despite the README claiming 'Zero dependencies'. Consumers who pass user-controlled or otherwise untrusted data into `threadContent` would expose their application to arbitrary code execution. Routing to human review so a maintainer can decide whether to publish a public advisory about the undocumented eval surface and the dependency mismatch. ## Source: ghsa-malware (336e8b05b5d99a33aed734a8bc6940554d865ad279346612362782f4cded5ff3) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it. Join the discussion | GCVE Database | 07/06/2026, 18:53:55 UTC Added: 07/06/2026, 23:03:21 UTC |
Showing 1 to 1 of 1 result