Malicious code in -john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena- (npm)
Malicious code was published in an npm package with a deceptive name referencing a movie title. The package was identified and cataloged by the OpenSSF malicious packages database.
- Disclosed
- Last updated
- Blast radius
- Unknown; depends on installation count of the malicious package
- Ecosystems
- Attack vectors
- Affected entities
- -john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-
A malicious npm package named "-john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-" was published to the npm registry containing malicious code. The package uses a deceptive name designed to appear as if it relates to a movie title, a common typosquatting and social engineering tactic.
The malicious package was identified and documented by the OpenSSF (Open Source Security Foundation) in their malicious packages database (MAL-2024-1690). The advisory was published on July 25, 2026, via GitHub's security advisory system.
This incident represents a direct supply chain compromise through a malicious package published to a public package registry. Users who installed this package would have been exposed to the malicious code.
Indicators of compromise
- Packages
- -john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-
Remediation
- Remove the malicious package from all systems where it was installed
- Audit systems that may have executed code from this package for signs of compromise
- Check npm audit logs and package-lock.json files for any installations of this package
- Update to a clean npm environment and verify package integrity before reinstalling dependencies
Sources
- GitHub Advisory GHSA-9fgr-54q8-5v83 · GitHub Advisory Database
Cite this entry
"Malicious code in -john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena- (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 25, 2026; last updated July 25, 2026. https://supplychainattack.org/incident/malicious-code-in-john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-e-1lykrw
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in sme-rko-finance-front-operations-feed-impl (npm)
The npm package sme-rko-finance-front-operations-feed-impl contained malicious code that downloads and executes platform-specific binary payloads via Cloudflare Workers or DNS-based staging channels. The malware obfuscates child_process imports and executes on require(), making it active upon installation.
npmCompromised package - containedcritical
Malicious code in sme-rko-finance-front-operations-overnight (npm)
The npm package sme-rko-finance-front-operations-overnight contains malicious code that downloads and executes attacker-controlled binaries from Cloudflare Workers hosts on package require. The payload uses obfuscation techniques to evade static analysis and includes environment-based gating to reduce detection.
npmCompromised package - containedcritical
Malicious code in sme-rko-finance-front-payment-registers-operations-domain (npm)
The npm package sme-rko-finance-front-payment-registers-operations-domain contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure. The package uses obfuscated string construction to hide command-and-control domains and implements a DNS-TXT fallback channel for payload delivery.
npmCompromised package - resolvedcritical
Malicious code in sme-rko-finance-front-operations-providers (npm)
The npm package sme-rko-finance-front-operations-providers contained malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers subdomains and DNS-TXT fallback channels upon require().
npmCompromised package