Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in @workoscalif/sudoku (npm)

@workoscalif/sudoku@1.4.0 on npm contained malicious code disguised as a sudoku puzzle generator. The package's postinstall script executed a large Go binary (33.6 MB) on x64 systems that contained an HTTP client and suspicious domain tokens, contradicting the legitimate C source code and documentation.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
All npm users who installed @workoscalif/sudoku@1.4.0
Ecosystems
Attack vectors
Affected entities
  • @workoscalif/sudoku · 1.4.0

@workoscalif/sudoku@1.4.0 was published to npm with a postinstall script that executes platform-specific binaries from the vendor/ directory during installation. The linux-x64 and darwin-x64 binaries are identical 33,648,788-byte Go ELF binaries, significantly larger than the legitimate C source code would produce (34-67 KB for arm64 binaries compiled from the included source).\n\nThe shipped binaries contain an HTTP client in their string table and suspicious domain-shaped tokens (uaguBrDY.tk, id7TJrH.ga, gIcKT3hfVC.co), indicating functionality unrelated to the documented sudoku puzzle generation. The package's README and C source code form a cover story that conceals the actual malicious payload executed on x64 hosts at install time.\n\nThe discrepancy between the legitimate C source (~250 lines of pure computation), the documented functionality (a small sockets/env-free generator), and the actual shipped binaries (Go-based with network capabilities) indicates intentional obfuscation of malicious functionality.\n\nThis incident was identified and credited to the OpenSSF's malicious-packages repository.

Indicators of compromise

Packages
  • @workoscalif/sudoku@1.4.0
Domains
  • uaguBrDY.tk
  • id7TJrH.ga
  • gIcKT3hfVC.co
Hashes
  • 05b69666193e8fa719c37df22833bf36a120b15e2408a9ecd47e34f140a44420

Remediation

  • Immediately uninstall @workoscalif/sudoku@1.4.0 from all systems
  • Audit npm install logs to identify systems that installed this package
  • Review network traffic from affected systems for connections to the identified suspicious domains (uaguBrDY.tk, id7TJrH.ga, gIcKT3hfVC.co)
  • Consider the affected systems potentially compromised and perform security assessment
  • Use npm audit to check for other malicious packages
  • Implement package verification and binary inspection in your supply chain security practices

Sources

  1. GitHub Advisory GHSA-8g32-6v5x-wx9c · GitHub Advisory Database

Cite this entry

"Malicious code in @workoscalif/sudoku (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 5, 2026; last updated August 5, 2026. https://supplychainattack.org/incident/malicious-code-in-workoscalif-sudoku-npm-xabysd

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. activecritical

    Malware in eslint-generate-prerelease

    Malware was discovered in the npm package eslint-generate-prerelease. Systems with this package installed or running should be considered fully compromised.

    npmCompromised package
  2. activecritical

    Malware in celonix-otp-react

    Malware discovered in the npm package celonix-otp-react. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  3. containedcritical

    Malware in resolve-audit

    The npm package resolve-audit was compromised and distributed with malware. Any system with the package installed or running should be considered fully compromised and all secrets/keys rotated immediately from a different machine.

    npmCompromised package
  4. resolvedcritical

    Malware in alphazone

    The npm package alphazone contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.

    npmCompromised package