Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'malicious-package'

View all threats tagged with 'malicious-package'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: malicious-package

Threats Tagged 'malicious-package'

Click on any threat for detailed analysis and mitigation recommendations

Malicious code in @idkruan-10/dpd-depconf-probe (npm)
0

The npm package @idkruan-10/dpd-depconf-probe contains malicious code that fully compromises any computer on which it is installed or running. The compromise allows an attacker to gain full control over the affected system. Immediate rotation of all secrets and keys stored on the compromised machine is necessary, using a different, clean computer. Removing the package alone does not guarantee removal of all malicious software introduced by it.

Join the discussion
Malicious code in op-ts-server-core (npm)
0

The npm package 'op-ts-server-core' contains malicious code that compromises any computer on which it is installed or running. The presence of this package indicates a full system compromise, requiring immediate rotation of all secrets and keys from a different, trusted machine. Simply removing the package does not guarantee removal of all malicious software introduced by it.

Join the discussion
Malicious code in service-home (npm)
0

The npm package 'service-home' contains malicious code that fully compromises any computer on which it is installed or running. The presence of this package indicates a complete security breach, necessitating immediate rotation of all secrets and keys from a separate, uncompromised system. Simply removing the package does not guarantee elimination of all malicious software introduced by it.

Join the discussion
Malicious code in @aircanada/navigation-handler (npm)
0

The npm package @aircanada/navigation-handler contains malicious code that compromises any computer on which it is installed or running. The presence of this package indicates a full system compromise, and all secrets and keys stored on the affected machine should be rotated immediately from a separate, trusted device. Removing the package alone does not guarantee removal of all malicious software introduced by its installation.

Join the discussion
Malicious code in @aircanada/components (npm)
0

The npm package '@aircanada/components' contains malicious code that compromises any computer on which it is installed or executed. The compromise is severe enough that all secrets and keys stored on the affected system should be rotated immediately from a separate, secure machine. Simply removing the package does not guarantee removal of all malicious artifacts or backdoors, as the attacker may have gained full control of the system.

Join the discussion
Malicious code in @aircanada/core (npm)
0

The npm package @aircanada/core contains malicious code that fully compromises any computer on which it is installed or running. The compromise is severe enough that all secrets and keys stored on the affected machine should be rotated immediately from a different, trusted device. Removing the package alone does not guarantee removal of all malicious software introduced by the package, as the attacker may have gained full control of the system.

Join the discussion
Malicious code in @cp-shared-14/frontend-ui (npm)
0

The npm package '@cp-shared-14/frontend-ui' version 6.3.4 has been identified as malicious. It communicates with domains linked to malicious activity and executes commands associated with harmful behavior. There is no CVSS score available for this threat. No official patch or remediation guidance is provided in the available data.

Join the discussion
Malicious code in cv-train (PyPI)
0

The cv-train package on PyPI contains malicious code that exfiltrates basic host information such as IP address and username upon installation or import. The package overrides the install command in setup.py to execute this malicious behavior. It serves no legitimate purpose beyond this data exfiltration.

Join the discussion
Malicious code in telegram-helper (PyPI)
0

The PyPI package 'telegram-helper' versions 0.1.1 and 0.1.2 contain malicious code that starts a Telegram bot to exfiltrate sensitive session files and browser cookies. This package acts as a remote access trojan (RAT) with capabilities to execute remote commands and steal browser data. It is designed to target victims via Telegram and uses a Telegram bot for command and control and data exfiltration.

Join the discussion
Malicious code in @jacksher/install-exec-poc (npm)
0

The npm package @jacksher/install-exec-poc contains malicious code that executes during installation. It performs DNS lookups and HTTPS requests to an attacker-controlled domain, leaking the installer's public IP and resolver metadata. It also uses execSync to run curl commands, establishing a shell-to-network primitive on the host. This behavior occurs unconditionally on install, compromising any system that installs the package. The package is labeled as a proof-of-concept but poses a real threat to consumers. Removal of the package does not guarantee full remediation due to potential persistent compromise.

Join the discussion

Showing 1 to 10 of 1859 results

Filters:Tag: malicious-package
Page 1 of 186
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses