Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malware in npm-sandbox-ping-c8f2a

Malware was distributed via the npm package npm-sandbox-ping-c8f2a. Systems with this package installed are considered fully compromised and require immediate remediation.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any system with the package installed or running
Ecosystems
Attack vectors
Affected entities
  • npm-sandbox-ping-c8f2a

A malicious npm package named npm-sandbox-ping-c8f2a was published to the npm registry. The package contains malware that grants full control of affected systems to an outside entity.\n\nAny computer with this package installed or running should be considered fully compromised. The advisory recommends immediate rotation of all secrets and keys from a different, unaffected computer. While the package should be removed, complete removal of all malicious software cannot be guaranteed due to the level of system compromise.\n\nThis incident was disclosed on 2026-06-18 via GitHub Security Advisory GHSA-w249-c3rp-ffwq.

Indicators of compromise

Packages
  • npm-sandbox-ping-c8f2a

Remediation

  • Immediately rotate all secrets, keys, and credentials from a different, unaffected computer
  • Remove the npm-sandbox-ping-c8f2a package from all affected systems
  • Perform a full security audit and malware scan of any system that had this package installed
  • Review system logs and network activity for signs of unauthorized access or data exfiltration
  • Consider full system reimaging if the package was installed on production or sensitive systems

Sources

  1. GitHub Advisory GHSA-w249-c3rp-ffwq · GitHub Advisory Database

Cite this entry

"Malware in npm-sandbox-ping-c8f2a." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed June 18, 2026; last updated June 20, 2026. https://supplychainattack.org/incident/malware-in-npm-sandbox-ping-c8f2a-ebuxo3

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in express-chai (npm)

    express-chai, a malicious npm package impersonating the pino logger middleware, contained obfuscated code that fetches and executes arbitrary code from a remote server (https://gray-dyane-31.tiiny.site/index.json) at middleware initialization time, granting full Node.js process access to an attacker.

    npmCompromised packageTyposquatting
  2. containedcritical

    Malicious code in xxdxax (npm)

    The npm package xxdxax contains obfuscated malicious code designed to target users of a specific WordPress site. When loaded in a browser on noviembrenacional.com, it exfiltrates session data and performs account takeover attacks via CSRF.

    npmCompromised package
  3. containedcritical

    Malicious code in squeez (npm)

    squeez@1.38.0 on npm contains malicious code in a postinstall hook that performs home-directory reconnaissance and fetches executable content from mutable GitHub URLs at install time. The package implements an install-time remote-content-fetch-and-execute pattern with capability to spawn child processes.

    npmCompromised package
  4. resolvedcritical

    Malicious code in dbk-ui-forms (npm)

    The npm package dbk-ui-forms version 99.0.1 contained malicious code that executed during installation, collecting sensitive host and environment information and exfiltrating it to an attacker-controlled domain. The package appears to be a dependency-confusion attack targeting internal build systems.

    npmCompromised packageDependency confusion