Skip to content
supplychainattack.orgSupply chain attack incident catalog
activecritical

Malware in pump-laserstream-parser

Malware discovered in the npm package pump-laserstream-parser. Systems with this package installed are considered fully compromised and require immediate remediation.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any system with the package installed or running
Ecosystems
Attack vectors
Affected entities
  • pump-laserstream-parser

The npm package pump-laserstream-parser has been identified as containing malware. According to the GitHub advisory, any computer with this package installed or running should be considered fully compromised.\n\nThe malware poses a critical risk to system security. All secrets and keys stored on affected computers should be rotated immediately from a different, uncompromised system. While the package should be removed, there is no guarantee that removal will eliminate all malicious software that may have been installed as a result of the package installation, as the attacker may have gained full control of the system.\n\nImmediate action is required for any systems that have installed or executed this package.

Indicators of compromise

Packages
  • pump-laserstream-parser

Remediation

  • Immediately isolate any computer that has installed or run pump-laserstream-parser from the network
  • Rotate all secrets, keys, and credentials from a different, uncompromised computer
  • Remove the pump-laserstream-parser package
  • Perform a full security audit and malware scan of affected systems
  • Review system logs for any unauthorized access or activity
  • Consider full system reimaging if compromise is confirmed

Sources

  1. GitHub Advisory GHSA-cwr6-c222-8hwf · GitHub Advisory Database

Cite this entry

"Malware in pump-laserstream-parser." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed June 26, 2026; last updated June 29, 2026. https://supplychainattack.org/incident/malware-in-pump-laserstream-parser-1t3xpz

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in vite-svg-parse (npm)

    The npm package vite-svg-parse contains malicious code that decodes base64 strings at runtime to install and execute an undeclared hidden dependency (node-internal-svg-loader) when the library's documented API is called. The attack conceals both the shell command and module name in base64 to evade static inspection.

    npmCompromised package
  2. containedcritical

    Malicious code in trimprompt (npm)

    The npm package trimprompt@1.0.47 contains malicious obfuscated code with install-time and load-time execution capabilities, including PowerShell spawning via postinstall hooks and host-reconnaissance/beaconing functionality via child_process and HTTP POST calls.

    npmCompromised package
  3. containedcritical

    Malicious code in xxdxax (npm)

    The npm package xxdxax contains obfuscated malicious code designed to target users of a specific WordPress site. When loaded in a browser on noviembrenacional.com, it exfiltrates session data and performs account takeover attacks via CSRF.

    npmCompromised package
  4. containedcritical

    Malicious code in squeez (npm)

    squeez@1.38.0 on npm contains malicious code in a postinstall hook that performs home-directory reconnaissance and fetches executable content from mutable GitHub URLs at install time. The package implements an install-time remote-content-fetch-and-execute pattern with capability to spawn child processes.

    npmCompromised package