Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in paysafe-gbp-virtual-assistant-lib-fe (npm)

The npm package paysafe-gbp-virtual-assistant-lib-fe version 2.0.4 was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
All users of paysafe-gbp-virtual-assistant-lib-fe npm package, particularly version 2.0.4
Ecosystems
Attack vectors
Affected entities
  • paysafe-gbp-virtual-assistant-lib-fe · 2.0.4

The npm package paysafe-gbp-virtual-assistant-lib-fe was identified as containing malicious code through multiple security analysis sources. Amazon Inspector and the OpenSSF Package Analysis project both flagged version 2.0.4 as malicious.\n\nAccording to the OpenSSF analysis, the package exhibits two primary indicators of malicious behavior: it communicates with a domain associated with malicious activity, and it executes one or more commands associated with malicious behavior. This suggests the package was either compromised or intentionally published with malicious intent.\n\nThe advisory was published on July 27, 2026, and is tracked under GitHub Security Advisory GHSA-cprr-jmxq-pj2p. The malicious package analysis is credited to the OpenSSF malicious-packages repository.

Indicators of compromise

Packages
  • paysafe-gbp-virtual-assistant-lib-fe@2.0.4

Remediation

  • Remove paysafe-gbp-virtual-assistant-lib-fe from all projects immediately
  • Audit all systems where this package was installed for signs of compromise
  • Review network logs for connections to the malicious domain(s) identified by the analysis
  • Rotate any credentials or sensitive data that may have been exposed
  • Update dependency management to prevent installation of this package
  • Monitor for any alternative or similarly-named packages that may be typosquatting variants

Sources

  1. GitHub Advisory GHSA-cprr-jmxq-pj2p · GitHub Advisory Database

Cite this entry

"Malicious code in paysafe-gbp-virtual-assistant-lib-fe (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 27, 2026; last updated July 28, 2026. https://supplychainattack.org/incident/malicious-code-in-paysafe-gbp-virtual-assistant-lib-fe-npm-c7iyts

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. activecritical

    Malware in @vaultflow/create-flow

    Malware discovered in the npm package @vaultflow/create-flow. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2. activecritical

    Malware in @vaultflow/update-flow

    Malware was discovered in the npm package @vaultflow/update-flow. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  3. resolvedcritical

    Malicious code in tempo-components (npm)

    The npm package tempo-components contained malicious code (poc.js) that collected host metadata and identity information and exfiltrated it to an external endpoint. The package performed system reconnaissance by capturing hostname, platform, and user identity before transmitting the data via HTTPS.

    npmCompromised package
  4. containedcritical

    Malicious code in @antv/g-webgl-compute (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g-webgl-compute, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit