Malicious code in @oyo_tech/oyochat_user (npm)
The npm package @oyo_tech/oyochat_user version 100.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.
- Disclosed
- Last updated
- Blast radius
- Unknown; depends on adoption of version 100.0.0
- Ecosystems
- Attack vectors
- Affected entities
- @oyo_tech/oyochat_user · 100.0.0
The OpenSSF Package Analysis project identified @oyo_tech/oyochat_user version 100.0.0 on npm as containing malicious code. The malicious behavior was detected through analysis of the package's runtime behavior and network communications.\n\nThe package was flagged because it communicates with a domain associated with malicious activity, indicating potential data exfiltration, command-and-control communication, or other malicious intent.\n\nThis incident was disclosed on 2026-08-18 via GitHub Security Advisory GHSA-wm7q-9397-cw9f and tracked in the OpenSSF malicious packages database.
Indicators of compromise
- Packages
- @oyo_tech/oyochat_user@100.0.0
Remediation
- Remove @oyo_tech/oyochat_user version 100.0.0 from all environments
- Audit project dependencies for any use of this package
- Review any systems that may have executed code from this package for signs of compromise
- Use npm audit or similar tools to identify affected projects
- Consider blocking this package name at the registry or organizational level if the maintainer cannot be verified
Sources
- GitHub Advisory GHSA-wm7q-9397-cw9f · GitHub Advisory Database
Cite this entry
"Malicious code in @oyo_tech/oyochat_user (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 18, 2026; last updated August 18, 2026. https://supplychainattack.org/incident/malicious-code-in-oyo-tech-oyochat-user-npm-oqw84g
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in github-policy-bot (npm)
The npm package github-policy-bot contained malicious code that exfiltrated host identifiers and environment metadata during installation via a postinstall script. The package name shadowed a legitimate Google-owned repository and was authored under a placeholder account claiming security research purposes.
npmCompromised packageTyposquatting - containedcritical
Malicious code in crypto-javas (npm)
The npm package crypto-javas contains malicious code in its postinstall hook and main entrypoint that harvests environment variables (including CI secrets like AWS_*, GITHUB_TOKEN, NPM_TOKEN) and exfiltrates them to an attacker-controlled backend. The package is presented deceptively as @wizlabs/js-crypto with a placeholder repository.
npmCompromised packageTyposquatting - containedcritical
Malicious code in flydev (npm)
The npm package flydev contains malicious code designed to destroy Windows systems. The package masquerades as a utility but executes destructive operations including filesystem deletion, process termination, memory exhaustion, and fork bombs when invoked.
npmCompromised package - containedcritical
Malicious code in npm-wold (npm)
npm-wold@1.1.1 contains malicious code in its postinstall script that fetches remote JSON from a hardcoded endpoint and dynamically invokes attacker-controlled functions with attacker-supplied arguments, enabling code execution at install time.
npmCompromised package