Malware in sjs-lint-build1
Malware discovered in the npm package sjs-lint-build1. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.
- Disclosed
- Last updated
- Blast radius
- Any system with the package installed or running
- Ecosystems
- Attack vectors
- Affected entities
- sjs-lint-build1
The npm package sjs-lint-build1 has been identified as containing malware. According to the GitHub Advisory (GHSA-g48w-hprp-f478), any computer with this package installed or running should be considered fully compromised.\n\nThe advisory recommends that all secrets and keys stored on affected computers be rotated immediately from a different, unaffected system. The package should be removed, though there is no guarantee that removal will eliminate all malicious software that may have been installed as a result of the initial compromise.\n\nThis represents a critical supply chain attack through a malicious package in the npm ecosystem.
Indicators of compromise
- Packages
- sjs-lint-build1
Remediation
- Immediately remove the sjs-lint-build1 package from all systems
- Rotate all secrets, API keys, and credentials from a clean, unaffected computer
- Audit system logs for unauthorized access or activity during the period the package was installed
- Consider the affected system(s) fully compromised and plan for complete rebuild or forensic analysis
- Check for any other suspicious packages or dependencies that may have been installed alongside this package
Sources
- GitHub Advisory GHSA-g48w-hprp-f478 · GitHub Advisory Database
Cite this entry
"Malware in sjs-lint-build1." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 6, 2026; last updated July 6, 2026. https://supplychainattack.org/incident/malware-in-sjs-lint-build1-1j7c7n
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in crypto-javas (npm)
The npm package crypto-javas contains malicious code in its postinstall hook and main entrypoint that harvests environment variables (including CI secrets like AWS_*, GITHUB_TOKEN, NPM_TOKEN) and exfiltrates them to an attacker-controlled backend. The package is presented deceptively as @wizlabs/js-crypto with a placeholder repository.
npmCompromised packageTyposquatting - containedcritical
Malicious code in flydev (npm)
The npm package flydev contains malicious code designed to destroy Windows systems. The package masquerades as a utility but executes destructive operations including filesystem deletion, process termination, memory exhaustion, and fork bombs when invoked.
npmCompromised package - resolvedcritical
Malicious code in ranux-dev (npm)
ranux-dev, an npm package, contained malicious code that substituted a popular WhatsApp library dependency with arbitrary code from an unaffiliated GitHub account. The package was heavily obfuscated and designed to harvest WhatsApp sessions and credentials from installers.
npmCompromised packageDependency confusion - containedcritical
Malicious code in npm-wold (npm)
npm-wold@1.1.1 contains malicious code in its postinstall script that fetches remote JSON from a hardcoded endpoint and dynamically invokes attacker-controlled functions with attacker-supplied arguments, enabling code execution at install time.
npmCompromised package