Malicious code in @anchor-ds/core (npm)
The npm package @anchor-ds/core was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.
- Disclosed
- Last updated
- Blast radius
- All users of @anchor-ds/core npm package
- Ecosystems
- Attack vectors
- Affected entities
- @anchor-ds/corenpm package
The npm package @anchor-ds/core was discovered to contain malicious code. The malicious package was identified by Amazon Inspector and subsequently reported to the OpenSSF malicious packages repository.\n\nThe incident was tracked under identifier MAL-2026-1585 in the OpenSSF malicious packages database. The discovery was made through automated security scanning and analysis.\n\nAny system or application that installed or used @anchor-ds/core from npm during the period the malicious version was available may be affected. Users should immediately audit their dependencies and remove or update the package.
Indicators of compromise
- Packages
- @anchor-ds/core
Remediation
- Remove @anchor-ds/core from all projects and dependencies
- Audit all systems that may have installed the malicious package
- Check for any suspicious activity or unauthorized access on affected systems
- Review npm package lock files and dependency trees for @anchor-ds/core
- Update to a clean version if a patched release becomes available
- Monitor the OpenSSF malicious packages database for updates on this incident
Sources
- GitHub Advisory GHSA-w4ff-rwjv-9xxj · GitHub Advisory Database
Cite this entry
"Malicious code in @anchor-ds/core (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 26, 2026; last updated July 26, 2026. https://supplychainattack.org/incident/malicious-code-in-anchor-ds-core-npm-sycdwk
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in sme-rko-finance-front-operations-special-payments (npm)
The npm package sme-rko-finance-front-operations-special-payments contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure upon require(). The package employed obfuscation techniques to evade static analysis and included dual dropper paths in both index.js and lib/telemetry.js.
npmCompromised package - activecritical
Malware in bnpl-blocks-desktop-bnpl-anchor-title
Malware discovered in the npm package bnpl-blocks-desktop-bnpl-anchor-title. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malicious code in sme-rko-finance-front-operations-notifications-models (npm)
The npm package sme-rko-finance-front-operations-notifications-models contained malicious code that acts as a native-binary dropper, downloading and executing platform-specific binaries from attacker-controlled Cloudflare Workers domains and DNS fallback servers upon package require.
npmCompromised package - resolvedcritical
Malicious code in sme-rko-finance-front-operations-penalty (npm)
The npm package sme-rko-finance-front-operations-penalty contained malicious code that downloads and executes platform-specific binaries on require(). The dropper uses obfuscated string concatenation and DNS fallback channels to retrieve payloads from attacker-controlled infrastructure.
npmCompromised package