Threats Tagged 'npm'
View all threats tagged with 'npm'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'npm'
Click on any threat for detailed analysis and mitigation recommendations
Malicious code in @ornikar/intl-config (npm) 0 The npm package @ornikar/intl-config versions 10.0.2 through 10.0.10 were compromised as part of a large-scale npm supply-chain worm campaign in August 2026. The malicious versions include a preinstall hook that downloads and executes an obfuscated Bun runtime payload which steals a wide range of credentials and secrets from the infected environment. This payload propagates by republishing other packages accessible via stolen npm tokens, causing widespread contamination. Any environment that installed these versions with install scripts enabled should be considered fully compromised, requiring immediate credential rotation and removal of the package. Join the discussion | GCVE Database | 08/04/2026, 15:12:46 UTC Added: 08/10/2026, 15:40:36 UTC |
Malicious code in @ornikar/react-native-svg-transformer (npm) 0 The npm package @ornikar/react-native-svg-transformer versions 1.0.6 through 1.0.13 were compromised as part of a large-scale npm supply-chain worm campaign in August 2026. The malicious versions include a preinstall script that downloads and executes an obfuscated payload designed to steal credentials and secrets from the host environment. This payload harvests various cloud and CI/CD credentials and uses stolen npm tokens to propagate further malicious package republishing. Any environment that installed these versions with install scripts enabled should be considered fully compromised and requires immediate credential rotation. Join the discussion | GCVE Database | 08/04/2026, 15:13:15 UTC Added: 08/10/2026, 15:40:36 UTC |
Malicious code in bnpl-blocks-desktop-bnpl-anchor-title (npm) 0 The npm package 'bnpl-blocks-desktop-bnpl-anchor-title' version 35.2.5 contains malicious code that downloads and executes a platform-specific binary from attacker-controlled infrastructure. This binary is fetched without verification, written to a temporary location, made executable, and executed detached from the main process. The package uses obfuscation techniques to evade detection and includes telemetry components as a cover. Any system with this package installed should be considered fully compromised, and all secrets on that system should be rotated immediately. Join the discussion | GCVE Database | 08/05/2026, 14:50:35 UTC Added: 08/10/2026, 15:40:36 UTC |
Malicious code in streak-map-cache (npm) 0 The npm package 'streak-map-cache' version 1.0.0 contains malicious code that executes a bundled Linux ELF binary acting as a RedShell command-and-control implant. This binary runs on every import, communicates with a hardcoded C2 server over HTTP, and supports remote shell commands, proxying, file exfiltration, credential harvesting, and persistence. The malicious binary is disguised as a 'native math accelerator' to evade detection. Any system with this package installed should be considered fully compromised. Join the discussion | GCVE Database | 08/06/2026, 15:31:13 UTC Added: 08/10/2026, 15:40:36 UTC |
Malicious code in @ssgw/icon (npm) 0 The npm package '@ssgw/icon' version 9.999.999 has been identified as malicious by the OpenSSF Package Analysis project. The package is flagged because it communicates with a domain associated with malicious activity. There is no information about a patch or remediation. No active exploits in the wild have been reported. The package is not a cloud service, and no CVSS score is available. Join the discussion | GCVE Database | 08/10/2026, 08:20:53 UTC Added: 08/10/2026, 15:40:29 UTC |
Malicious code in tokocrytodev (npm) 0 The npm package 'tokocrytodev' version 1.0.0 contains malicious code that, upon execution, establishes a command-and-control (C2) communication channel to a remote server. It executes arbitrary commands received from the attacker, harvests private key files from various sensitive directories, and exfiltrates them encrypted. The package then uses stolen Ethereum private keys to transfer funds from compromised wallets to a hardcoded attacker address. Errors are silently suppressed to avoid detection. Join the discussion | GCVE Database | 08/10/2026, 11:50:11 UTC Added: 08/10/2026, 15:40:12 UTC |
Malicious code in simple-date-formatter-new-10 (npm) 0 The npm package simple-date-formatter-new-10 version 1.0.0 contains malicious code that executes during installation. It opens a reverse shell to a remote attacker and exfiltrates SSH keys and user information to a command and control server. The advertised date-formatting functionality is a cover for these attack payloads. Join the discussion | GCVE Database | 08/10/2026, 11:53:39 UTC Added: 08/10/2026, 15:40:12 UTC |
Malicious code in simple-date-formatter-new-9 (npm) 0 The npm package 'simple-date-formatter-new-9' version 1.0.0 contains malicious code that executes a reverse shell to a hardcoded remote IP address during installation. It also collects and exfiltrates the installer's ~/.ssh directory listing along with username and platform information to the same remote server. This behavior occurs automatically during the npm install process, enabling remote command execution on the installer's host. Join the discussion | GCVE Database | 08/10/2026, 11:53:49 UTC Added: 08/10/2026, 15:40:12 UTC |
Malicious code in specials-resources-server (npm) 0 The npm package specials-resources-server version 35.8.1 is a malicious package that acts as a staged remote code execution dropper disguised as an analytics SDK. Upon import, it fetches and executes a binary payload from anonymous Cloudflare Workers subdomains without integrity verification, writing it to temporary directories and executing it with elevated privileges. This behavior results in full system compromise. Immediate removal and secret rotation are advised, but full remediation cannot be guaranteed due to potential persistent compromise. Join the discussion | GCVE Database | 08/08/2026, 17:27:55 UTC Added: 08/10/2026, 15:40:11 UTC |
Malicious code in env-local (npm) 0 The npm package 'env-local' impersonates the popular 'dotenv' package but contains malicious code that captures the installer's screen every 3 seconds and sends the images along with system information to a remote server. It also polls the server for mouse and keyboard input commands, which it replays locally to give remote interactive control of the desktop. On Windows, it persists by creating a VBS launcher and adding a registry entry to auto-execute on user logon. Join the discussion | GCVE Database | 08/10/2026, 11:53:57 UTC Added: 08/10/2026, 15:40:11 UTC |
Showing 1 to 10 of 2022 results