Malicious code in nc-verify-127942 (npm)
The npm package nc-verify-127942 contained malicious code in a postinstall lifecycle hook that executed arbitrary code on installation, exfiltrating network identifiers to an attacker-controlled Burp Collaborator endpoint. The package was labeled as a proof-of-concept for RCE verification.
- Disclosed
- Last updated
- Blast radius
- Any developer or CI environment that installed nc-verify-127942
- Ecosystems
- Attack vectors
- Affected entities
- nc-verify-127942npm package containing malicious postinstall hook
The npm package nc-verify-127942 was published with intentionally malicious code designed to demonstrate remote code execution capabilities. The package declared a postinstall lifecycle hook that automatically executed the install-cb.js script upon installation without requiring user interaction.
The install-cb.js script performed an HTTPS request and DNS lookup to a Burp Collaborator subdomain (nc-verify-127942.owoemjgpf2c4qxqet92hexzvym4dsq6skvoa2cr.oastify.com) under oastify.com. This action confirmed code execution on the installer's host and leaked network identifiers including the source IP address and DNS resolver information to an operator-controlled out-of-band endpoint.
The package metadata explicitly identified it as a proof-of-concept for RCE verification. Installation in any developer or CI environment would trigger the malicious beacon automatically, making this a critical supply chain risk for any system that installed the package.
This incident was identified and credited to the OpenSSF's malicious-packages repository.
Indicators of compromise
- Packages
- nc-verify-127942
- Domains
- oastify.com
- nc-verify-127942.owoemjgpf2c4qxqet92hexzvym4dsq6skvoa2cr.oastify.com
Remediation
- Immediately uninstall nc-verify-127942 from all systems and CI/CD pipelines
- Audit npm install logs and package-lock.json files to identify any installations of nc-verify-127942
- Review network logs for outbound connections to oastify.com subdomains from the time of installation
- Regenerate any credentials or secrets that may have been exposed on affected systems
- Implement npm package scanning and allowlisting policies to prevent installation of suspicious or unvetted packages
- Monitor for any follow-up malicious packages with similar naming patterns
Sources
- GitHub Advisory GHSA-phh7-pw76-hr8h · GitHub Advisory Database
Cite this entry
"Malicious code in nc-verify-127942 (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 13, 2026; last updated August 13, 2026. https://supplychainattack.org/incident/malicious-code-in-nc-verify-127942-npm-jwx2iq
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malware in userbotjs-jun
The npm package userbotjs-jun was found to contain malware, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in async-mutex-v2
Malware was discovered in the npm package async-mutex-v2. Systems with this package installed are considered fully compromised and require immediate remediation including credential rotation and package removal.
npmCompromised package - containedcritical
Malware in a.poltoradnev-package-c
Malware was discovered in the npm package a.poltoradnev-package-c. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in bucket-protocol-sdk-v2
Malware discovered in the npm package bucket-protocol-sdk-v2. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package