Malicious code in array-sort-helper (npm)
The npm package array-sort-helper version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.
- Disclosed
- Last updated
- Blast radius
- All npm users who installed array-sort-helper version 1.0.0
- Ecosystems
- Attack vectors
- Affected entities
- array-sort-helper · 1.0.0
The OpenSSF Package Analysis project identified array-sort-helper version 1.0.0 on npm as a malicious package. Analysis revealed that the package contains code designed to communicate with domains associated with malicious activity and execute commands consistent with malicious behavior patterns.
The package was flagged through the OpenSSF's malicious-packages repository, which tracks confirmed malicious packages across major package ecosystems. This represents a direct compromise of the package itself rather than an account takeover or build system compromise.
Users who installed array-sort-helper version 1.0.0 may have been exposed to malicious code execution on their systems. The package should be removed and replaced with a safe alternative or the functionality reimplemented.
Indicators of compromise
- Packages
- array-sort-helper@1.0.0
Remediation
- Remove array-sort-helper version 1.0.0 from all projects and dependencies
- Audit systems that may have executed this package for signs of compromise
- Replace with a trusted alternative package or implement the sorting functionality directly
- Review npm audit logs for installation of this package
- Update package-lock.json and yarn.lock files to remove references to this version
Sources
- GitHub Advisory GHSA-mx6g-xr3v-fc2f · GitHub Advisory Database
Cite this entry
"Malicious code in array-sort-helper (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 28, 2026; last updated July 28, 2026. https://supplychainattack.org/incident/malicious-code-in-array-sort-helper-npm-bcijcn
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- activecritical
Malware in @omniwatch-wick/cli
Malware discovered in the npm package @omniwatch-wick/cli. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in chain-manager
Malware discovered in the npm package chain-manager. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malicious code in toll_free (npm)
The npm package toll_free version 1.0.1 was identified as malicious by the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.
npmCompromised package - containedcritical
Malicious code in blots (npm)
The npm package 'blots' version 2.1.0 was identified by the OpenSSF Package Analysis project as containing malicious code that executes commands associated with malicious behavior. The package has been flagged in the OpenSSF malicious packages database.
npmCompromised package