Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malware in nodemon-sudo

The npm package nodemon-sudo contained malware that could fully compromise any system where it was installed or executed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any system with the package installed or running
Ecosystems
Attack vectors
Affected entities
  • nodemon-sudonpm package containing malware

The npm package nodemon-sudo was found to contain malware. According to the GitHub advisory (GHSA-8228-4gjp-c339), any computer with this package installed or running should be considered fully compromised.\n\nThe malware grants full control of the affected system to an outside entity. All secrets, keys, and credentials stored on compromised systems should be rotated immediately from a different, unaffected computer.\n\nWhile the package should be removed, there is no guarantee that removal will eliminate all malicious software that may have been installed as a result of the initial compromise. Systems should be treated as potentially containing persistent backdoors or other malware.\n\nThe advisory was published on 2026-07-09 via GitHub's security advisory system.

Indicators of compromise

Packages
  • nodemon-sudo

Remediation

  • Remove the nodemon-sudo package immediately
  • Treat any system that had this package installed or running as fully compromised
  • Rotate all secrets, keys, and credentials from a different, unaffected computer
  • Perform a full security audit and malware scan of affected systems
  • Consider rebuilding or replacing affected systems if possible
  • Review system logs and access logs for signs of unauthorized activity during the period the package was installed

Sources

  1. GitHub Advisory GHSA-8228-4gjp-c339 · GitHub Advisory Database

Cite this entry

"Malware in nodemon-sudo." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 9, 2026; last updated July 9, 2026. https://supplychainattack.org/incident/malware-in-nodemon-sudo-ecyg6c

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in poc-ch4rlygr (npm)

    The npm package poc-ch4rlygr contained malicious code that exfiltrated system metadata and environment variables (including secrets like AWS_*, NPM_TOKEN, GITHUB_TOKEN) to a hardcoded OAST endpoint on require/import.

    npmCompromised package
  2. containedcritical

    Malicious code in gpt-terminal-cli (npm)

    gpt-terminal-cli, an npm package advertised as an AI chat CLI, contains malicious code that installs a persistent remote access implant with extensive capabilities including reverse shell, credential theft, keylogging, and antiforensics. The implant communicates with a hardcoded C2 server and supports dynamic C2 rotation via DNS dead-drop.

    npmCompromised packageMalicious commit
  3. resolvedcritical

    Malicious code in lib-frontsga (npm)

    Malicious npm package 'lib-frontsga' version 9.999.999 exploits dependency confusion to target organizations with an internal package of the same name. A preinstall/postinstall script collects host and CI environment identifiers and exfiltrates them via DNS and HTTP callbacks to an attacker-controlled domain.

    npmCompromised packageDependency confusion
  4. resolvedcritical

    Malicious code in express-chai (npm)

    express-chai, a malicious npm package impersonating the pino logger middleware, contained obfuscated code that fetches and executes arbitrary code from a remote server (https://gray-dyane-31.tiiny.site/index.json) at middleware initialization time, granting full Node.js process access to an attacker.

    npmCompromised packageTyposquatting