Skip to content
supplychainattack.orgSupply chain attack incident catalog
activecritical

Malware in logform-core

Malware was discovered in the npm package logform-core. Systems with this package installed or running are considered fully compromised and require immediate remediation.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any system with logform-core installed or running is considered fully compromised.
Ecosystems
Attack vectors
Affected entities
  • logform-core

A critical malware incident was identified in the npm package logform-core. According to the GitHub Advisory (GHSA-f2wx-p6h3-rgg2), any computer with this package installed or running should be considered fully compromised.\n\nThe advisory recommends immediate action: all secrets and keys stored on affected computers should be rotated from a different, uncompromised system. While the package should be removed, there is no guarantee that removal will eliminate all malicious software that may have been installed as a result of the compromise.\n\nThe incident was published on July 30, 2026, and remains active.

Indicators of compromise

Packages
  • logform-core

Remediation

  • Immediately rotate all secrets and keys from a different, uncompromised computer
  • Remove the logform-core package from all affected systems
  • Conduct a full security audit of any system that had logform-core installed
  • Monitor affected systems for signs of unauthorized access or persistence mechanisms
  • Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved

Sources

  1. GitHub Advisory GHSA-f2wx-p6h3-rgg2 · GitHub Advisory Database

Cite this entry

"Malware in logform-core." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 30, 2026; last updated July 30, 2026. https://supplychainattack.org/incident/malware-in-logform-core-9d0rgj

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malware in svelte-metric-map

    Malware was discovered in the npm package svelte-metric-map. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2. containedcritical

    Malware in streak-metrics-core

    Malware was discovered in the npm package streak-metrics-core. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  3. containedcritical

    Malware in svelte-streak-metric

    Malware was discovered in the npm package svelte-streak-metric. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  4. containedcritical

    Malware in @404c3s4r/testxxx

    Malware was discovered in the npm package @404c3s4r/testxxx. Systems with this package installed or running are considered fully compromised, requiring immediate secret rotation and package removal.

    npmCompromised package