Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in nc-verify-127942 (npm)

The npm package nc-verify-127942 contained malicious code in a postinstall lifecycle hook that executed arbitrary code on installation, exfiltrating network identifiers to an attacker-controlled Burp Collaborator endpoint. The package was labeled as a proof-of-concept for RCE verification.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any developer or CI environment that installed nc-verify-127942
Ecosystems
Attack vectors
Affected entities
  • nc-verify-127942npm package containing malicious postinstall hook

The npm package nc-verify-127942 was published with intentionally malicious code designed to demonstrate remote code execution capabilities. The package declared a postinstall lifecycle hook that automatically executed the install-cb.js script upon installation without requiring user interaction.

The install-cb.js script performed an HTTPS request and DNS lookup to a Burp Collaborator subdomain (nc-verify-127942.owoemjgpf2c4qxqet92hexzvym4dsq6skvoa2cr.oastify.com) under oastify.com. This action confirmed code execution on the installer's host and leaked network identifiers including the source IP address and DNS resolver information to an operator-controlled out-of-band endpoint.

The package metadata explicitly identified it as a proof-of-concept for RCE verification. Installation in any developer or CI environment would trigger the malicious beacon automatically, making this a critical supply chain risk for any system that installed the package.

This incident was identified and credited to the OpenSSF's malicious-packages repository.

Indicators of compromise

Packages
  • nc-verify-127942
Domains
  • oastify.com
  • nc-verify-127942.owoemjgpf2c4qxqet92hexzvym4dsq6skvoa2cr.oastify.com

Remediation

  • Immediately uninstall nc-verify-127942 from all systems and CI/CD pipelines
  • Audit npm install logs and package-lock.json files to identify any installations of nc-verify-127942
  • Review network logs for outbound connections to oastify.com subdomains from the time of installation
  • Regenerate any credentials or secrets that may have been exposed on affected systems
  • Implement npm package scanning and allowlisting policies to prevent installation of suspicious or unvetted packages
  • Monitor for any follow-up malicious packages with similar naming patterns

Sources

  1. GitHub Advisory GHSA-phh7-pw76-hr8h · GitHub Advisory Database

Cite this entry

"Malicious code in nc-verify-127942 (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 13, 2026; last updated August 13, 2026. https://supplychainattack.org/incident/malicious-code-in-nc-verify-127942-npm-jwx2iq

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malware in userbotjs-jun

    The npm package userbotjs-jun was found to contain malware, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2. containedcritical

    Malware in async-mutex-v2

    Malware was discovered in the npm package async-mutex-v2. Systems with this package installed are considered fully compromised and require immediate remediation including credential rotation and package removal.

    npmCompromised package
  3. containedcritical

    Malware in a.poltoradnev-package-c

    Malware was discovered in the npm package a.poltoradnev-package-c. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  4. activecritical

    Malware in bucket-protocol-sdk-v2

    Malware discovered in the npm package bucket-protocol-sdk-v2. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package