Malicious code in @finxsecdemo/utils (npm)
The npm package @finxsecdemo/utils version 1.0.2 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.
- Disclosed
- Last updated
- Blast radius
- Unknown; depends on adoption of @finxsecdemo/utils 1.0.2
- Ecosystems
- Attack vectors
- Affected entities
- @finxsecdemo/utils · 1.0.2
The OpenSSF Package Analysis project identified @finxsecdemo/utils version 1.0.2 on npm as containing malicious code. The malicious behavior was detected through analysis of the package's runtime behavior and network communications.
The package was flagged because it communicates with a domain associated with malicious activity, indicating potential data exfiltration, command-and-control communication, or other malicious intent.
The incident was disclosed on 2026-07-29 via GitHub Security Advisory GHSA-qccg-fq42-3rgc and tracked in the OpenSSF malicious packages repository.
Indicators of compromise
- Packages
- @finxsecdemo/utils@1.0.2
Remediation
- Remove @finxsecdemo/utils 1.0.2 from all projects and dependencies
- Audit project dependencies to identify any use of the affected version
- Review any systems that may have executed code from this package for signs of compromise
- Use npm audit or similar tools to detect the malicious package in dependency trees
- Consider the security posture of any systems that installed or ran this package
Sources
- GitHub Advisory GHSA-qccg-fq42-3rgc · GitHub Advisory Database
Cite this entry
"Malicious code in @finxsecdemo/utils (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 29, 2026; last updated July 29, 2026. https://supplychainattack.org/incident/malicious-code-in-finxsecdemo-utils-npm-sa2ub3
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malware in polymarket-risk-manager
Malware was discovered in the npm package polymarket-risk-manager, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malicious code in toll_free (npm)
The npm package toll_free version 1.0.1 was identified as malicious by the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.
npmCompromised package - containedcritical
Malware in poly-kelly
Malware was discovered in the npm package poly-kelly. The package grants full system compromise to attackers and should be considered a critical threat to any system where it is installed or running.
npmCompromised package - containedcritical
Malware in @bowozzz/baileys
The npm package @bowozzz/baileys contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package