Threats Tagged 'malicious-package'
View all threats tagged with 'malicious-package'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'malicious-package'
Click on any threat for detailed analysis and mitigation recommendations
Malicious code in kotanku (PyPI) 0 The kotanku package on PyPI version 0.1.0 contains malicious code that exfiltrates cryptocurrency wallet files during import. This behavior is part of a campaign identified as 2026-08-kotanku, which uses a Telegram bot for exfiltration. No official patch or remediation guidance is provided. There is no evidence of active exploitation in the wild at this time. Join the discussion | GCVE Database | 08/09/2026, 20:39:54 UTC Added: 08/10/2026, 15:40:38 UTC |
Malicious code in @ornikar/intl-config (npm) 0 The npm package @ornikar/intl-config versions 10.0.2 through 10.0.10 were compromised as part of a large-scale npm supply-chain worm campaign in August 2026. The malicious versions include a preinstall hook that downloads and executes an obfuscated Bun runtime payload which steals a wide range of credentials and secrets from the infected environment. This payload propagates by republishing other packages accessible via stolen npm tokens, causing widespread contamination. Any environment that installed these versions with install scripts enabled should be considered fully compromised, requiring immediate credential rotation and removal of the package. Join the discussion | GCVE Database | 08/04/2026, 15:12:46 UTC Added: 08/10/2026, 15:40:36 UTC |
Malicious code in @ornikar/react-native-svg-transformer (npm) 0 The npm package @ornikar/react-native-svg-transformer versions 1.0.6 through 1.0.13 were compromised as part of a large-scale npm supply-chain worm campaign in August 2026. The malicious versions include a preinstall script that downloads and executes an obfuscated payload designed to steal credentials and secrets from the host environment. This payload harvests various cloud and CI/CD credentials and uses stolen npm tokens to propagate further malicious package republishing. Any environment that installed these versions with install scripts enabled should be considered fully compromised and requires immediate credential rotation. Join the discussion | GCVE Database | 08/04/2026, 15:13:15 UTC Added: 08/10/2026, 15:40:36 UTC |
Malicious code in bnpl-blocks-desktop-bnpl-anchor-title (npm) 0 The npm package 'bnpl-blocks-desktop-bnpl-anchor-title' version 35.2.5 contains malicious code that downloads and executes a platform-specific binary from attacker-controlled infrastructure. This binary is fetched without verification, written to a temporary location, made executable, and executed detached from the main process. The package uses obfuscation techniques to evade detection and includes telemetry components as a cover. Any system with this package installed should be considered fully compromised, and all secrets on that system should be rotated immediately. Join the discussion | GCVE Database | 08/05/2026, 14:50:35 UTC Added: 08/10/2026, 15:40:36 UTC |
Malicious code in streak-map-cache (npm) 0 The npm package 'streak-map-cache' version 1.0.0 contains malicious code that executes a bundled Linux ELF binary acting as a RedShell command-and-control implant. This binary runs on every import, communicates with a hardcoded C2 server over HTTP, and supports remote shell commands, proxying, file exfiltration, credential harvesting, and persistence. The malicious binary is disguised as a 'native math accelerator' to evade detection. Any system with this package installed should be considered fully compromised. Join the discussion | GCVE Database | 08/06/2026, 15:31:13 UTC Added: 08/10/2026, 15:40:36 UTC |
Malicious code in @ssgw/icon (npm) 0 The npm package '@ssgw/icon' version 9.999.999 has been identified as malicious by the OpenSSF Package Analysis project. The package is flagged because it communicates with a domain associated with malicious activity. There is no information about a patch or remediation. No active exploits in the wild have been reported. The package is not a cloud service, and no CVSS score is available. Join the discussion | GCVE Database | 08/10/2026, 08:20:53 UTC Added: 08/10/2026, 15:40:29 UTC |
Malicious code in pytablute (PyPI) 0 The pytablute package version 1.0.3 on PyPI contains malicious code that executes upon import or use. This code downloads a secondary malicious script and runs a background process that periodically connects to a remote host to receive and execute further commands. The package is obfuscated and designed to execute remote commands on the victim's machine, indicating clear malicious intent. Join the discussion | GCVE Database | 08/10/2026, 08:37:18 UTC Added: 08/10/2026, 15:40:29 UTC |
Malicious code in chaintest (PyPI) 0 The chaintest package on PyPI version 0.1.0 contains malicious code functioning as a cryptocurrency infostealer. It exfiltrates sensitive data from browsers, including cryptowallet extensions and local storage, as well as standalone applications like password managers and cryptowallets. The malware achieves persistence on different platforms, runs a keylogger that alters copied cryptocurrency addresses to attacker-controlled ones, and can execute remote commands from a command-and-control server. It also exfiltrates SSH keys, installs malicious browser extensions, and shares similarities with a known DPRK-linked campaign. Join the discussion | GCVE Database | 08/10/2026, 10:37:01 UTC Added: 08/10/2026, 15:40:14 UTC |
Malicious code in tokocrytodev (npm) 0 The npm package 'tokocrytodev' version 1.0.0 contains malicious code that, upon execution, establishes a command-and-control (C2) communication channel to a remote server. It executes arbitrary commands received from the attacker, harvests private key files from various sensitive directories, and exfiltrates them encrypted. The package then uses stolen Ethereum private keys to transfer funds from compromised wallets to a hardcoded attacker address. Errors are silently suppressed to avoid detection. Join the discussion | GCVE Database | 08/10/2026, 11:50:11 UTC Added: 08/10/2026, 15:40:12 UTC |
Malicious code in simple-date-formatter-new-10 (npm) 0 The npm package simple-date-formatter-new-10 version 1.0.0 contains malicious code that executes during installation. It opens a reverse shell to a remote attacker and exfiltrates SSH keys and user information to a command and control server. The advertised date-formatting functionality is a cover for these attack payloads. Join the discussion | GCVE Database | 08/10/2026, 11:53:39 UTC Added: 08/10/2026, 15:40:12 UTC |
Showing 1 to 10 of 5689 results