npm_malware Profile Banner
npm malware Profile
npm malware

@npm_malware

Followers
2K
Following
25
Media
1
Statuses
7K

📣 We tweet malicious packages detected on npm in real-time. 🚨 Not affiliated with @npmjs or @github. 🛡 Powered by the @SocketSecurity threat feed. ✨

Joined August 2022
Don't wanna be here? Send us removal request.
@npm_malware
npm malware
3 hours
⚠️ New threat detected: docs-component-size-limit-dialog@1.1.0 ⚠️. The code executes system commands and sends their output to a suspicious remote server, indicating potential malicious behavior. The code is not obfuscated, but it poses a high securit.
Tweet card summary image
socket.dev
Version: 1.1.0 was published by xml69120. Start using Socket to analyze docs-component-size-limit-dialog and its dependencies to secure your app from ...
0
0
0
@npm_malware
npm malware
4 hours
⚠️ New threat detected: @​zalando-internal/z-shop-ui@991.0.1 ⚠️. This file harvests system details (os.hostname(), os.userInfo().username, Windows domain and admin status via child_process.execSync, platform and __dirname), globally disables TLS certi.
Tweet card summary image
socket.dev
Package created for ethical hacking purposes only for this bug bounty platform: https://hackerone.com/zalando. For any concerns please contact user.dc...
0
0
2
@npm_malware
npm malware
7 hours
⚠️ New threat detected: nyc-config@6.1.0 ⚠️. This file gathers detailed OS and network information (including hostname, user details, and IP addresses) and sends it to hardcoded endpoints (e.g., http://23[.]22[.]251[.]177:8080/jpd[.]php and http://23[.
Tweet card summary image
socket.dev
Npm Package. Version: 6.1.0 was published by unknown. Start using Socket to analyze nyc-config and its dependencies to secure your app from supply cha...
0
1
1
@npm_malware
npm malware
12 hours
⚠️ Malware removed from npm: backdoor-client@0.1.28 ⚠️. The code is designed to copy a suspiciously named 'backdoor-service-worker.js' file to a parent project's public directory. While the code itself does not exhibit direct malicious activity, the '.
Tweet card summary image
socket.dev
This template provides a minimal setup to get React working in Vite with HMR and some ESLint rules. Version: 0.1.28 was published by tengweiherr. Star...
0
0
0
@npm_malware
npm malware
13 hours
⚠️ New threat detected: ikyy@4.0.8 ⚠️. The code exfiltrates user-provided JavaScript code to a suspicious external server at sl[.]rzkyfdlh[.]tech without user consent or transparency. The function accepts JavaScript code as input, URL-encodes it, and .
Tweet card summary image
socket.dev
Simple module random. Version: 4.0.8 was published by ikyy. Start using Socket to analyze ikyy and its dependencies to secure your app from supply cha...
0
0
0
@npm_malware
npm malware
23 hours
⚠️ New threat detected: revo_ahahaptcha@1.0.4 ⚠️. The code is intended for bypassing Roblox's captcha system, potentially for automating account creation or other automated actions, which may violate terms of service. The code also disables TLS/SSL ce.
Tweet card summary image
socket.dev
Some strange stuff. Version: 1.0.4 was published by quew. Start using Socket to analyze revo_ahahaptcha and its dependencies to secure your app from s...
0
0
0
@npm_malware
npm malware
1 day
⚠️ New threat detected: fca-anjelo-remake@40.0.0 ⚠️. The code demonstrates risky behaviors such as executing shell commands based on environment variables and global configurations without proper validation, automatic installation, and execution of pa.
Tweet card summary image
socket.dev
Facebook Chat Api Được Remake Bới anjelo Chống Get (available) Và Pay Acc (maybe?). Version: 40.0.0 was published by anjelochat. Start using Socket to...
0
1
1
@npm_malware
npm malware
1 day
⚠️ New threat detected: namira-account-reactjs@1.7.2 ⚠️. The code contains potential security risks due to insufficient input validation and handling of sensitive user data. It is crucial to review and improve the input validation and data handling me.
Tweet card summary image
socket.dev
Namira Software Corporation Account ReactJS Package. Version: 1.7.2 was published by amir.abolhasani.1368. Start using Socket to analyze namira-accoun...
0
0
0
@npm_malware
npm malware
1 day
⚠️ New threat detected: nyc-config@5.7.0 ⚠️. This file gathers detailed OS and network information (including hostname, user details, and IP addresses) and sends it to hardcoded endpoints (e.g., http://23[.]22[.]251[.]177:8080/jpd[.]php and http://23[.
Tweet card summary image
socket.dev
Npm Package. Version: 5.7.0 was published by unknown. Start using Socket to analyze nyc-config and its dependencies to secure your app from supply cha...
0
2
4
@npm_malware
npm malware
1 day
⚠️ New threat detected: @​indigo-multi/fonts@3.1.2 ⚠️. The file gathers sensitive environment details by calling os.userInfo().username, os.hostname(), and process.cwd(), concatenates them with pipe separators, converts the result to a hex string (tru.
Tweet card summary image
socket.dev
Version: 3.1.2 was published by epi-unitaire. Start using Socket to analyze @indigo-multi/fonts and its dependencies to secure your app from supply ch...
0
0
0
@npm_malware
npm malware
1 day
⚠️ New threat detected: phone-mockup-react-js@1.0.2 ⚠️. This source code is malicious malware that performs data theft by harvesting sensitive browser and wallet files from the victim's machine and exfiltrating them to attacker-controlled servers. The.
Tweet card summary image
socket.dev
This module is to plug all node modules. Version: 1.0.2 was published by miketoken1. Start using Socket to analyze phone-mockup-react-js and its depen...
0
0
2
@npm_malware
npm malware
2 days
⚠️ New threat detected: @​airslate/front-locales@9.9.10 ⚠️. The code appears to be designed for collecting system information and secretly sending it to an external server via DNS requests, which is a common tactic in data exfiltration and malware com.
Tweet card summary image
socket.dev
This is a Proof of Concept (PoC) package. Version: 9.9.10 was published by grandiosedisclose. Start using Socket to analyze @airslate/front-locales an...
0
0
0
@npm_malware
npm malware
3 days
⚠️ New threat detected: coin-hive@1.9.0 ⚠️. The code embeds a cryptocurrency mining script (CoinHive) into all served pages, constituting cryptojacking malware. It serves a local miner.js script with an incorrect content-type header. The behavior is m.
Tweet card summary image
socket.dev
Mine cryptocurrency [Monero (XMR)](https://getmonero.org/) using [CoinHive](https://coinhive.com/) from node.js. Version...
0
0
0
@npm_malware
npm malware
3 days
⚠️ New threat detected: @​pwa-ib/eslint-plugin-compat@1.99.99 ⚠️. Package was removed from the registry. This script collects sensitive environment details—current working directory, package name and version, system hostname and current user—and encod.
Tweet card summary image
socket.dev
Version: 1.99.99 was published by panya. Start using Socket to analyze @pwa-ib/eslint-plugin-compat and its dependencies to secure your app from suppl...
0
0
1
@npm_malware
npm malware
4 days
⚠️ New threat detected: json-log-stream@1.0.12 ⚠️. This file contains malicious code that functions as a backdoor with data exfiltration and remote code execution capabilities. The code systematically collects sensitive system information including al.
Tweet card summary image
socket.dev
A fast and lightweight JSON logger with streaming support, built for high-performance Node.js applications. Version: 1.0.12 was published by fanhaomin...
0
0
0
@npm_malware
npm malware
4 days
⚠️ New threat detected: vite-tsconfig-log@1.0.6 ⚠️. This package was removed from the registry. This obfuscated JavaScript module uses Node’s os and axios libraries plus dynamic imports to:. 1. Retrieve the machine’s hostname and user info. 2. Fetc.
Tweet card summary image
socket.dev
Advanced log generator for log engine. Version: 1.0.6 was published by millos. Start using Socket to analyze vite-tsconfig-log and its dependencies to...
0
1
1
@npm_malware
npm malware
4 days
⚠️ New threat detected: autodraintokentarget@1.0.2 ⚠️. Automated Solana token draining malware that continuously monitors a victim's wallet and transfers all SPL tokens to an attacker-controlled wallet. The malware operates by connecting to a Solana R.
Tweet card summary image
socket.dev
Version: 1.0.2 was published by ahmadakbarpadilah. Start using Socket to analyze autodraintokentarget and its dependencies to secure your app from sup...
0
0
0
@npm_malware
npm malware
4 days
⚠️ New threat detected: outdoc@1.0.1 ⚠️. When the environment variable IS_OUTDOC is set to ‘true’, this code installs a low-level async_hooks monitor on TickObject events to intercept HTTP traffic. It inspects internal Node.js HTTP stream buffers and .
Tweet card summary image
socket.dev
Auto-generate OpenAPI document for Node.js service from the local testing. Version: 1.0.1 was published by wwayne. Start using Socket to analyze outdo...
0
0
0
@npm_malware
npm malware
4 days
⚠️ Malware removed from npm: vite-tsconfig-log@1.0.10 ⚠️. This file contains malicious code that operates as spyware and a remote access backdoor. The heavily obfuscated code collects sensitive system information including hostname, username, public I.
Tweet card summary image
socket.dev
Advanced log generator for log engine. Version: 1.0.10 was published by millos. Start using Socket to analyze vite-tsconfig-log and its dependencies t...
0
0
0
@npm_malware
npm malware
5 days
⚠️ New threat detected: @​epic-typeface/brutal@2.944.0 ⚠️. The code is malicious and designed to stealthily exfiltrate environment variables via DNS queries to a remote server. This constitutes a serious security risk and data theft. The obfuscation t.
Tweet card summary image
socket.dev
Version: 2.944.0 was published by heplc. Start using Socket to analyze @epic-typeface/brutal and its dependencies to secure your app from supply chain...
0
0
0