Malicious code in -whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-index-main (npm)
Malicious code was published in the npm package "-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-index-main". The package was identified and cataloged by the OpenSSF malicious packages database.
- Disclosed
- Last updated
- Blast radius
- Unknown; depends on installation count of the malicious package.
- Ecosystems
- Attack vectors
- Affected entities
- -whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-index-main
A malicious npm package with the name "-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-index-main" was published to the npm registry. The package contained malicious code and was identified as part of the OpenSSF's malicious packages tracking effort.\n\nThe package name appears to be a typosquatting or deceptive naming attempt, mimicking content related to the movie "John Wick: Chapter 4" to attract downloads. This is a common tactic used to distribute malware through package managers.\n\nThe incident was documented in the OpenSSF malicious packages repository (MAL-2024-1693) and subsequently reported via GitHub Security Advisories (GHSA-qj66-7hrg-7gqc).
Indicators of compromise
- Packages
- -whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-index-main
Remediation
- Remove the package from your project dependencies immediately
- Audit your project for any installations of this package
- Review npm audit logs for any installations of this malicious package
- If installed, assume compromise and rotate any credentials or secrets that may have been exposed
- Update your npm lockfile after removing the package
Sources
- GitHub Advisory GHSA-qj66-7hrg-7gqc · GitHub Advisory Database
Cite this entry
"Malicious code in -whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-index-main (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 25, 2026; last updated July 25, 2026. https://supplychainattack.org/incident/malicious-code-in-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-a-pl9l24
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena- (npm)
Malicious code was published in an npm package with a deceptive name referencing a movie title. The package was identified and documented by the OpenSSF malicious packages project.
npmCompromised package - resolvedcritical
Malicious code in -john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-love (npm)
A malicious npm package with a deceptive name containing movie-related keywords was published to the npm registry. The package contained malicious code and was identified by the OpenSSF malicious packages project.
npmCompromised package - resolvedcritical
Malicious code in -john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena- (npm)
Malicious code was published in an npm package with a deceptive name referencing a movie title. The package was identified and cataloged by the OpenSSF malicious packages database.
npmCompromised package - containedcritical
Malicious code in -pem-misa (npm)
The npm package -pem-misa contains malicious code designed to automatically generate and republish derivative packages with randomized names to the npm registry. The attack is part of a broader tea.xyz token reward campaign that flooded npm with similar malicious packages.
npmCompromised packageMalicious commit