Malicious code in svharness (npm)
The svharness npm package contained malicious code that silently exfiltrated source code and repository metadata to a hardcoded third-party LLM gateway (api.laozhang.ai) during normal CLI usage, along with a live API credential embedded in the package.
- Disclosed
- Last updated
- Blast radius
- All users of svharness npm package who ran documented build or wizard commands
- Ecosystems
- Attack vectors
- Affected entities
- svharnessnpm package with malicious code in dist/wiki/defaults.js
The svharness npm package contained intentional malicious functionality that transmitted sensitive data without user consent. When users ran the documented svharness build --baseline or svharness wizard commands, the tool's default 'tasks' wiki mode would scan and bundle the caller's repository—including the file tree, README, and file excerpts up to ~24KB—and POST that content to a hardcoded URL https://api.laozhang.ai/v1/chat/completions using a hardcoded Bearer API key embedded in dist/wiki/defaults.js.\n\nThis data exfiltration occurred automatically unless the user explicitly overrode the destination via CLI flag, environment variable, or .env file. The package also redistributed a live third-party API credential (sk-... token) to every installer, allowing anyone who extracted it to reuse it against the attacker's infrastructure.\n\nA secondary plain-HTTP relay (http://markitdown.desaysz.site) in the convert subcommand further exposed user documents by uploading them over an unencrypted channel to an author-controlled host.\n\nThe incident was identified and credited to the OpenSSF's malicious-packages repository.
Indicators of compromise
- Packages
- svharness
- Domains
- api.laozhang.ai
- markitdown.desaysz.site
Remediation
- Immediately uninstall svharness from all systems
- Audit any source code or repository metadata that may have been transmitted to api.laozhang.ai
- Rotate any credentials or API keys that may have been exposed during package installation
- Review npm audit logs for svharness installation and usage
- Do not use svharness or any successor packages from the same author without thorough security review
Sources
- GitHub Advisory GHSA-4v2r-cgqf-hmf4 · GitHub Advisory Database
Cite this entry
"Malicious code in svharness (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 27, 2026; last updated July 27, 2026. https://supplychainattack.org/incident/malicious-code-in-svharness-npm-pq3f4z
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in @antv/g-webgl-compute (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g-webgl-compute, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
npmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g2-ssr (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g2-ssr, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
npmAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g6-extension-3d (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g6-extension-3d, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
npmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/gi-assets-basic (npm)
A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/gi-assets-basic, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
npmOtherAccount takeoverCompromised packageMalicious commit