Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in epic-common (npm)

The npm package epic-common was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; depends on adoption of affected versions
Ecosystems
Attack vectors
Affected entities
  • epic-common

The npm package epic-common was discovered to contain malicious code. The malicious package was identified by Amazon Inspector and subsequently reported to the OpenSSF malicious packages repository.\n\nThe incident was tracked under OpenSSF identifier MAL-2025-49124. The malicious code was detected and the finding was published on 2026-08-17.\n\nUsers of epic-common should immediately audit their dependencies, identify affected versions, and upgrade to a patched or alternative version if available.

Indicators of compromise

Packages
  • epic-common

Remediation

  • Identify all projects using epic-common and determine which versions are installed
  • Remove or upgrade epic-common to a known-safe version if available
  • Audit systems that may have executed code from affected versions for signs of compromise
  • Monitor for suspicious activity on systems that installed the malicious package
  • Consider using alternative packages if epic-common is no longer maintained securely

Sources

  1. GitHub Advisory GHSA-5ffc-9gj9-xfvj · GitHub Advisory Database

Cite this entry

"Malicious code in epic-common (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 17, 2026; last updated August 17, 2026. https://supplychainattack.org/incident/malicious-code-in-epic-common-npm-7flzh6

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in github-policy-bot (npm)

    The npm package github-policy-bot contained malicious code that exfiltrated host identifiers and environment metadata during installation via a postinstall script. The package name shadowed a legitimate Google-owned repository and was authored under a placeholder account claiming security research purposes.

    npmCompromised packageTyposquatting
  2. containedcritical

    Malicious code in crypto-javas (npm)

    The npm package crypto-javas contains malicious code in its postinstall hook and main entrypoint that harvests environment variables (including CI secrets like AWS_*, GITHUB_TOKEN, NPM_TOKEN) and exfiltrates them to an attacker-controlled backend. The package is presented deceptively as @wizlabs/js-crypto with a placeholder repository.

    npmCompromised packageTyposquatting
  3. containedcritical

    Malicious code in flydev (npm)

    The npm package flydev contains malicious code designed to destroy Windows systems. The package masquerades as a utility but executes destructive operations including filesystem deletion, process termination, memory exhaustion, and fork bombs when invoked.

    npmCompromised package
  4. containedcritical

    Malicious code in npm-wold (npm)

    npm-wold@1.1.1 contains malicious code in its postinstall script that fetches remote JSON from a hardcoded endpoint and dynamically invokes attacker-controlled functions with attacker-supplied arguments, enabling code execution at install time.

    npmCompromised package