Malware in dowload_ebok_programming_in_haskell_second_edition_by_graham_hutton_c19wm
A malicious npm package named dowload_ebok_programming_in_haskell_second_edition_by_graham_hutton_c19wm was published containing malware. Systems with this package installed are considered fully compromised and require immediate remediation.
- Disclosed
- Last updated
- Blast radius
- Any system with the package installed
- Ecosystems
- Attack vectors
- Affected entities
- dowload_ebok_programming_in_haskell_second_edition_by_graham_hutton_c19wm
A malicious npm package with the name dowload_ebok_programming_in_haskell_second_edition_by_graham_hutton_c19wm was identified and reported via GitHub Advisory GHSA-7cqx-w44w-2w4m. The package contains malware that grants full control of affected systems to an outside entity.
Any computer that has installed or run this package should be considered fully compromised. The advisory recommends immediate rotation of all secrets and keys from a different, uncompromised computer. While the package should be removed, there is no guarantee that removal will eliminate all malicious software that may have been installed as a result of the initial compromise.
The package name appears to be a typosquatting attempt, mimicking a legitimate programming book title to deceive users into installation.
Indicators of compromise
- Packages
- dowload_ebok_programming_in_haskell_second_edition_by_graham_hutton_c19wm
Remediation
- Immediately remove the package from all affected systems
- Rotate all secrets, API keys, and credentials from a different, uncompromised computer
- Perform a full security audit and malware scan of any system that had this package installed
- Review system logs and network traffic for signs of unauthorized access or data exfiltration
- Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved
Sources
- GitHub Advisory GHSA-7cqx-w44w-2w4m · GitHub Advisory Database
Cite this entry
"Malware in dowload_ebok_programming_in_haskell_second_edition_by_graham_hutton_c19wm." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 10, 2026; last updated July 10, 2026. https://supplychainattack.org/incident/malware-in-dowload-ebok-programming-in-haskell-second-edition-by-graham-hutton-c-65tptk
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in sme-rko-finance-front-operations-feed-impl (npm)
The npm package sme-rko-finance-front-operations-feed-impl contained malicious code that downloads and executes platform-specific binary payloads via Cloudflare Workers or DNS-based staging channels. The malware obfuscates child_process imports and executes on require(), making it active upon installation.
npmCompromised package - containedcritical
Malicious code in sme-rko-finance-front-operations-overnight (npm)
The npm package sme-rko-finance-front-operations-overnight contains malicious code that downloads and executes attacker-controlled binaries from Cloudflare Workers hosts on package require. The payload uses obfuscation techniques to evade static analysis and includes environment-based gating to reduce detection.
npmCompromised package - containedcritical
Malicious code in sme-rko-finance-front-payment-registers-operations-domain (npm)
The npm package sme-rko-finance-front-payment-registers-operations-domain contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure. The package uses obfuscated string construction to hide command-and-control domains and implements a DNS-TXT fallback channel for payload delivery.
npmCompromised package - resolvedcritical
Malicious code in sme-rko-finance-front-operations-providers (npm)
The npm package sme-rko-finance-front-operations-providers contained malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers subdomains and DNS-TXT fallback channels upon require().
npmCompromised package