Malicious code in identitysecuretokenserv (npm)
The npm package identitysecuretokenserv version 10.0.0 was found to contain malicious code that communicates with domains associated with malicious activity and executes commands associated with malicious behavior. The package was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project.
- Disclosed
- Last updated
- Blast radius
- All users of identitysecuretokenserv npm package version 10.0.0 and potentially other versions
- Ecosystems
- Attack vectors
- Affected entities
- identitysecuretokenserv · 10.0.0
The npm package identitysecuretokenserv was identified as containing malicious code by multiple security sources. Amazon Inspector and the OpenSSF Package Analysis project both flagged version 10.0.0 as malicious.\n\nAccording to the OpenSSF Package Analysis findings, the package exhibits two key malicious behaviors: it communicates with a domain associated with malicious activity, and it executes one or more commands associated with malicious behavior. This indicates active post-installation compromise capabilities.\n\nThe package was published on GitHub's advisory system (GHSA-rqm7-j2qp-74f2) and credited to the OpenSSF malicious packages database. The incident was disclosed on 2026-07-27.
Indicators of compromise
- Packages
- identitysecuretokenserv@10.0.0
Remediation
- Immediately remove identitysecuretokenserv from all projects and dependencies
- Audit all systems where identitysecuretokenserv version 10.0.0 was installed for signs of compromise
- Review network logs for connections to the malicious domain(s) identified by OpenSSF
- Regenerate any credentials or secrets that may have been exposed on affected systems
- Check npm audit and dependency trees for any transitive dependencies on this package
- Monitor for any suspicious command execution or network activity on systems that installed this package
Sources
- GitHub Advisory GHSA-rqm7-j2qp-74f2 · GitHub Advisory Database
Cite this entry
"Malicious code in identitysecuretokenserv (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 27, 2026; last updated July 28, 2026. https://supplychainattack.org/incident/malicious-code-in-identitysecuretokenserv-npm-xxx6lu
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- activecritical
Malware in @vaultflow/create-flow
Malware discovered in the npm package @vaultflow/create-flow. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @vaultflow/update-flow
Malware was discovered in the npm package @vaultflow/update-flow. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - resolvedcritical
Malicious code in tempo-components (npm)
The npm package tempo-components contained malicious code (poc.js) that collected host metadata and identity information and exfiltrated it to an external endpoint. The package performed system reconnaissance by capturing hostname, platform, and user identity before transmitting the data via HTTPS.
npmCompromised package - containedcritical
Malicious code in @antv/g-webgl-compute (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g-webgl-compute, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit