Malware in @moxfive-llc/common
Malware was discovered in the npm package @moxfive-llc/common. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
- Disclosed
- Last updated
- Blast radius
- Any system with the package installed or running
- Ecosystems
- Attack vectors
- Affected entities
- @moxfive-llc/common
A malware-laden version of the npm package @moxfive-llc/common was published and made available to users. The advisory indicates that any system with this package installed or running should be considered fully compromised, with potential for complete system takeover by an external entity.\n\nThe advisory recommends immediate removal of the package and rotation of all secrets and keys from a different, uncompromised computer. However, due to the severity of the compromise, there is no guarantee that removing the package alone will eliminate all malicious software that may have been installed as a result.\n\nThis is classified as a compromised-package incident affecting the npm ecosystem.
Indicators of compromise
- Packages
- @moxfive-llc/common
Remediation
- Remove the @moxfive-llc/common package immediately
- Rotate all secrets, keys, and credentials from a different, uncompromised computer
- Assume full system compromise and perform forensic analysis
- Review system logs for unauthorized access or activity
- Consider full system rebuild if the package was installed on production or sensitive systems
Sources
- GitHub Advisory GHSA-x9jj-732w-pjvr · GitHub Advisory Database
Cite this entry
"Malware in @moxfive-llc/common." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 1, 2026; last updated August 1, 2026. https://supplychainattack.org/incident/malware-in-moxfive-llc-common-4pmxel
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malware in vite-config-svg
The npm package vite-config-svg was found to contain malware, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in @peptide-packets/js-unimode
Malware discovered in the npm package @peptide-packets/js-unimode. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @peptide-packets/peptide-modify
Malware discovered in the npm package @peptide-packets/peptide-modify. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @sudoughnym/enviro-demo
Malware discovered in the npm package @sudoughnym/enviro-demo. Systems with this package installed are considered fully compromised and may have given outside entities full control of the computer.
npmCompromised package