Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in svharness (npm)

The svharness npm package contained malicious code that silently exfiltrated source code and repository metadata to a hardcoded third-party LLM gateway (api.laozhang.ai) during normal CLI usage, along with a live API credential embedded in the package.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
All users of svharness npm package who ran documented build or wizard commands
Ecosystems
Attack vectors
Affected entities
  • svharnessnpm package with malicious code in dist/wiki/defaults.js

The svharness npm package contained intentional malicious functionality that transmitted sensitive data without user consent. When users ran the documented svharness build --baseline or svharness wizard commands, the tool's default 'tasks' wiki mode would scan and bundle the caller's repository—including the file tree, README, and file excerpts up to ~24KB—and POST that content to a hardcoded URL https://api.laozhang.ai/v1/chat/completions using a hardcoded Bearer API key embedded in dist/wiki/defaults.js.\n\nThis data exfiltration occurred automatically unless the user explicitly overrode the destination via CLI flag, environment variable, or .env file. The package also redistributed a live third-party API credential (sk-... token) to every installer, allowing anyone who extracted it to reuse it against the attacker's infrastructure.\n\nA secondary plain-HTTP relay (http://markitdown.desaysz.site) in the convert subcommand further exposed user documents by uploading them over an unencrypted channel to an author-controlled host.\n\nThe incident was identified and credited to the OpenSSF's malicious-packages repository.

Indicators of compromise

Packages
  • svharness
Domains
  • api.laozhang.ai
  • markitdown.desaysz.site

Remediation

  • Immediately uninstall svharness from all systems
  • Audit any source code or repository metadata that may have been transmitted to api.laozhang.ai
  • Rotate any credentials or API keys that may have been exposed during package installation
  • Review npm audit logs for svharness installation and usage
  • Do not use svharness or any successor packages from the same author without thorough security review

Sources

  1. GitHub Advisory GHSA-4v2r-cgqf-hmf4 · GitHub Advisory Database

Cite this entry

"Malicious code in svharness (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 27, 2026; last updated July 27, 2026. https://supplychainattack.org/incident/malicious-code-in-svharness-npm-pq3f4z

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in @antv/g-webgl-compute (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g-webgl-compute, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    npmOtherAccount takeoverCompromised packageMalicious commit
  2. containedcritical

    Malicious code in @antv/g2-ssr (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g2-ssr, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    npmAccount takeoverCompromised packageMalicious commit
  3. containedcritical

    Malicious code in @antv/g6-extension-3d (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g6-extension-3d, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    npmOtherAccount takeoverCompromised packageMalicious commit
  4. containedcritical

    Malicious code in @antv/gi-assets-basic (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/gi-assets-basic, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    npmOtherAccount takeoverCompromised packageMalicious commit