Malicious code in @innocarpe/deepseek-build (npm)
The npm package @innocarpe/deepseek-build contained malicious code in its postinstall script that exfiltrated environment variables and host identifier data via POST requests at install time. The package was identified by Amazon Inspector and credited to OpenSSF's malicious-packages repository.
- Disclosed
- Last updated
- Blast radius
- Any developer or system that installed @innocarpe/deepseek-build during the malicious period; potential exposure of environment variables and host identifiers.
- Ecosystems
- Attack vectors
- Affected entities
- @innocarpe/deepseek-build
The npm package @innocarpe/deepseek-build contained malicious code embedded in its postinstall lifecycle hook (scripts/postinstall.js). The script required the child_process module and issued POST requests carrying environment and host identifier data during package installation.\n\nThis behavior matches a reconnaissance beacon pattern rather than a legitimate build step. The malicious activity occurred automatically at install time, exfiltrating local process state and system identifiers without user knowledge or consent.\n\nThe package was identified by Amazon Inspector and reported through the OpenSSF's malicious-packages repository (MAL-2026-13420). The discovery was credited to OpenSSF.
Indicators of compromise
- Packages
- @innocarpe/deepseek-build
Remediation
- Immediately uninstall @innocarpe/deepseek-build from all systems where it was installed
- Audit environment variables and secrets that may have been exposed during installation
- Review outbound network logs for POST requests to unknown destinations during the installation window
- Rotate any credentials or tokens that may have been present in environment variables at the time of installation
- Check npm audit logs and package-lock.json for the presence of this package
- Consider using npm audit to scan for other malicious packages
Sources
- GitHub Advisory GHSA-xgww-8hrg-m827 · GitHub Advisory Database
Cite this entry
"Malicious code in @innocarpe/deepseek-build (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 6, 2026; last updated August 7, 2026. https://supplychainattack.org/incident/malicious-code-in-innocarpe-deepseek-build-npm-5mpeap
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in epic-common-node (npm)
The npm package epic-common-node was found to contain malicious code. The package has been identified and reported through GitHub Security Advisory GHSA-m36g-mhjr-ww2c.
npmCompromised package - containedcritical
Malware in @siwatfa/yorn
Malware was discovered in the npm package @siwatfa/yorn. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in @zizie071/libsignal-node
The npm package @zizie071/libsignal-node contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - resolvedcritical
Malicious code in epic-sso (npm)
The npm package epic-sso was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.
npmCompromised package