Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in @oyo_tech/oyochat_user (npm)

The npm package @oyo_tech/oyochat_user version 100.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; depends on adoption of version 100.0.0
Ecosystems
Attack vectors
Affected entities
  • @oyo_tech/oyochat_user · 100.0.0

The OpenSSF Package Analysis project identified @oyo_tech/oyochat_user version 100.0.0 on npm as containing malicious code. The malicious behavior was detected through analysis of the package's runtime behavior and network communications.\n\nThe package was flagged because it communicates with a domain associated with malicious activity, indicating potential data exfiltration, command-and-control communication, or other malicious intent.\n\nThis incident was disclosed on 2026-08-18 via GitHub Security Advisory GHSA-wm7q-9397-cw9f and tracked in the OpenSSF malicious packages database.

Indicators of compromise

Packages
  • @oyo_tech/oyochat_user@100.0.0

Remediation

  • Remove @oyo_tech/oyochat_user version 100.0.0 from all environments
  • Audit project dependencies for any use of this package
  • Review any systems that may have executed code from this package for signs of compromise
  • Use npm audit or similar tools to identify affected projects
  • Consider blocking this package name at the registry or organizational level if the maintainer cannot be verified

Sources

  1. GitHub Advisory GHSA-wm7q-9397-cw9f · GitHub Advisory Database

Cite this entry

"Malicious code in @oyo_tech/oyochat_user (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 18, 2026; last updated August 18, 2026. https://supplychainattack.org/incident/malicious-code-in-oyo-tech-oyochat-user-npm-oqw84g

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in github-policy-bot (npm)

    The npm package github-policy-bot contained malicious code that exfiltrated host identifiers and environment metadata during installation via a postinstall script. The package name shadowed a legitimate Google-owned repository and was authored under a placeholder account claiming security research purposes.

    npmCompromised packageTyposquatting
  2. containedcritical

    Malicious code in crypto-javas (npm)

    The npm package crypto-javas contains malicious code in its postinstall hook and main entrypoint that harvests environment variables (including CI secrets like AWS_*, GITHUB_TOKEN, NPM_TOKEN) and exfiltrates them to an attacker-controlled backend. The package is presented deceptively as @wizlabs/js-crypto with a placeholder repository.

    npmCompromised packageTyposquatting
  3. containedcritical

    Malicious code in flydev (npm)

    The npm package flydev contains malicious code designed to destroy Windows systems. The package masquerades as a utility but executes destructive operations including filesystem deletion, process termination, memory exhaustion, and fork bombs when invoked.

    npmCompromised package
  4. containedcritical

    Malicious code in npm-wold (npm)

    npm-wold@1.1.1 contains malicious code in its postinstall script that fetches remote JSON from a hardcoded endpoint and dynamically invokes attacker-controlled functions with attacker-supplied arguments, enabling code execution at install time.

    npmCompromised package