Malware in @postman-app-monolith/renderer
Malware was discovered in the npm package @postman-app-monolith/renderer. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
- Disclosed
- Last updated
- Blast radius
- Any system with the package installed or running
- Ecosystems
- Attack vectors
- Affected entities
- @postman-app-monolith/renderer
A malicious package named @postman-app-monolith/renderer was published to npm and contains malware. According to the GitHub advisory, any computer that has installed or run this package should be considered fully compromised.\n\nThe advisory recommends that all secrets and keys stored on affected computers be rotated immediately from a different, uncompromised system. While the package should be removed, there is no guarantee that removal will eliminate all malicious software that may have been installed as a result of the initial compromise.\n\nThis represents a critical supply chain attack through a compromised npm package with potential for complete system compromise.
Indicators of compromise
- Packages
- @postman-app-monolith/renderer
Remediation
- Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer
- Remove the @postman-app-monolith/renderer package from all affected systems
- Audit system logs for any suspicious activity or unauthorized access
- Consider full system reimaging if the package was installed on production or sensitive systems
- Review npm package dependencies to ensure no other malicious packages are present
Sources
- GitHub Advisory GHSA-jv69-xjcr-5hx9 · GitHub Advisory Database
Cite this entry
"Malware in @postman-app-monolith/renderer." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed June 29, 2026; last updated June 29, 2026. https://supplychainattack.org/incident/malware-in-postman-app-monolith-renderer-12eftl
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in lodash-lib (npm)
lodash-lib@1.0.0 on npm is a typosquatting package containing malicious code that executes a postinstall script to download and execute a Windows binary. The package masquerades as the legitimate lodash library and uses obfuscation techniques to hide its malicious behavior.
npmCompromised packageTyposquatting - containedcritical
Malicious code in chalk-core (npm)
chalk-core@1.0.0 is a typosquatting package masquerading as the popular chalk library. It contains malicious postinstall scripts that decode and execute arbitrary binaries on Windows and WSL systems, with command-and-control beaconing to 193.70.34.101:20099.
npmTyposquattingCompromised package - resolvedcritical
Malicious code in typesript-core (npm)
typesript-core@1.0.0 is a typosquat of the legitimate 'typescript' package containing malicious postinstall code that downloads and executes a Windows PE binary from a remote C2 server (193.70.34.101:20099). The package uses XOR encoding to obfuscate the payload URL and C2 communication, and includes a PowerShell bridge for WSL environments.
npmTyposquattingCompromised package - containedcritical
Malicious code in raectjs (npm)
The raectjs npm package contained malicious code in its postinstall script that exfiltrated system information and downloaded a Windows executable from an attacker-controlled GitHub account. The package had no legitimate purpose and was designed solely as a dropper.
npmCompromised package