Malicious code in epic-common (npm)
The npm package epic-common was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.
- Disclosed
- Last updated
- Blast radius
- Unknown; depends on adoption of affected versions
- Ecosystems
- Attack vectors
- Affected entities
- epic-common
The npm package epic-common was discovered to contain malicious code. The malicious package was identified by Amazon Inspector and subsequently reported to the OpenSSF malicious packages repository.\n\nThe incident was tracked under OpenSSF identifier MAL-2025-49124. The malicious code was detected and the finding was published on 2026-08-17.\n\nUsers of epic-common should immediately audit their dependencies, identify affected versions, and upgrade to a patched or alternative version if available.
Indicators of compromise
- Packages
- epic-common
Remediation
- Identify all projects using epic-common and determine which versions are installed
- Remove or upgrade epic-common to a known-safe version if available
- Audit systems that may have executed code from affected versions for signs of compromise
- Monitor for suspicious activity on systems that installed the malicious package
- Consider using alternative packages if epic-common is no longer maintained securely
Sources
- GitHub Advisory GHSA-5ffc-9gj9-xfvj · GitHub Advisory Database
Cite this entry
"Malicious code in epic-common (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 17, 2026; last updated August 17, 2026. https://supplychainattack.org/incident/malicious-code-in-epic-common-npm-7flzh6
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in github-policy-bot (npm)
The npm package github-policy-bot contained malicious code that exfiltrated host identifiers and environment metadata during installation via a postinstall script. The package name shadowed a legitimate Google-owned repository and was authored under a placeholder account claiming security research purposes.
npmCompromised packageTyposquatting - containedcritical
Malicious code in crypto-javas (npm)
The npm package crypto-javas contains malicious code in its postinstall hook and main entrypoint that harvests environment variables (including CI secrets like AWS_*, GITHUB_TOKEN, NPM_TOKEN) and exfiltrates them to an attacker-controlled backend. The package is presented deceptively as @wizlabs/js-crypto with a placeholder repository.
npmCompromised packageTyposquatting - containedcritical
Malicious code in flydev (npm)
The npm package flydev contains malicious code designed to destroy Windows systems. The package masquerades as a utility but executes destructive operations including filesystem deletion, process termination, memory exhaustion, and fork bombs when invoked.
npmCompromised package - containedcritical
Malicious code in npm-wold (npm)
npm-wold@1.1.1 contains malicious code in its postinstall script that fetches remote JSON from a hardcoded endpoint and dynamically invokes attacker-controlled functions with attacker-supplied arguments, enabling code execution at install time.
npmCompromised package