Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in @finxsecdemo/utils (npm)

The npm package @finxsecdemo/utils version 1.0.2 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; depends on adoption of @finxsecdemo/utils 1.0.2
Ecosystems
Attack vectors
Affected entities
  • @finxsecdemo/utils · 1.0.2

The OpenSSF Package Analysis project identified @finxsecdemo/utils version 1.0.2 on npm as containing malicious code. The malicious behavior was detected through analysis of the package's runtime behavior and network communications.

The package was flagged because it communicates with a domain associated with malicious activity, indicating potential data exfiltration, command-and-control communication, or other malicious intent.

The incident was disclosed on 2026-07-29 via GitHub Security Advisory GHSA-qccg-fq42-3rgc and tracked in the OpenSSF malicious packages repository.

Indicators of compromise

Packages
  • @finxsecdemo/utils@1.0.2

Remediation

  • Remove @finxsecdemo/utils 1.0.2 from all projects and dependencies
  • Audit project dependencies to identify any use of the affected version
  • Review any systems that may have executed code from this package for signs of compromise
  • Use npm audit or similar tools to detect the malicious package in dependency trees
  • Consider the security posture of any systems that installed or ran this package

Sources

  1. GitHub Advisory GHSA-qccg-fq42-3rgc · GitHub Advisory Database

Cite this entry

"Malicious code in @finxsecdemo/utils (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 29, 2026; last updated July 29, 2026. https://supplychainattack.org/incident/malicious-code-in-finxsecdemo-utils-npm-sa2ub3

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malware in polymarket-risk-manager

    Malware was discovered in the npm package polymarket-risk-manager, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2. containedcritical

    Malicious code in toll_free (npm)

    The npm package toll_free version 1.0.1 was identified as malicious by the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.

    npmCompromised package
  3. containedcritical

    Malware in poly-kelly

    Malware was discovered in the npm package poly-kelly. The package grants full system compromise to attackers and should be considered a critical threat to any system where it is installed or running.

    npmCompromised package
  4. containedcritical

    Malware in @bowozzz/baileys

    The npm package @bowozzz/baileys contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package