This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries.


1. noblox-asset.js (npm)

noblox-asset.js impersonates the noblox.js Roblox API wrapper: package.json copies the legitimate package's description, homepage (github.com/noblox/noblox.js), and repository metadata while shipping a heavily obfuscated postinstall.mjs. On npm install, the postinstall script performs sandbox-evasion checks (recent-boot gating <15 minutes, parent-process allowlist, running-process checks for x64dbg/ollydbg/ida/procmon, VirtualBox/VMware/QEMU/Xen/Parallels/Hyper-V registry/driver/MAC-OUI checks) and, on non-sandbox hosts, downloads https://trlxgames.netlify.app/TRLX.exe to os.tmpdir()/NOBLOX_CLI.exe and spawns it detached with stdio ignored and unref, so the process survives after npm exits. The download destination is unrelated to the impersonated project's publisher, the binary is unpinned and unverified, and the script uses obfuscator.io-style _0xNNNN string-array indirection to hide the flow.


2. jexkcode (npm)

Versions 1.0.1 through 1.1.4 of jexkcode automatically follow a hard-coded WhatsApp newsletter whenever a WhatsApp connection opens. The package waits three seconds and calls newsletterFollow without obtaining user consent or exposing a configuration option. The README advertises newsletter support but does not disclose this automatic account modification. Versions through 1.1.1 used a malformed newsletter JID; version 1.1.2 corrected it. Subsequent commits removed both failure and success logs, so version 1.1.4 performs the automatic follow without visible output. This behavior is unrelated to the package's stated functionality and modifies the user's WhatsApp account without authorization.


3. noxleyss (npm)

This package contains concealed WhatsApp channel-following behavior consistent with engagement abuse. Two independent paths automatically follow and mute channels using the connected account.


4. plogme (npm)

plogme is a renamed fork of the Baileys WhatsApp Web library from the same publisher-controlled family as @crysnovax/baileys (MAL-2026-15917), and versions 1.0.0 through 1.0.3 carry the same forced-follow and fingerprint modules. lib/Utils/channel-policy.js (javascript-obfuscator output, identical to the file in MAL-2026-15917) hardcodes the publisher's WhatsApp newsletter channels 120363423670814885@newsletter and 120363402922206865@newsletter and exports followCrysnovaxTrustedChannels(); lib/Socket/socket.js invokes it from the connection.update handler, so the user's own authenticated WhatsApp account silently follows both channels on every successful connection, with no opt-out. lib/Utils/integrity.js hashes hostname, platform, arch, cpu model and Node version into a machine fingerprint and POSTs it with the package identity to https://bailey.crysnovax.link/api/v1/verify on every socket connect. The obfuscated follow module was decoded, not executed.


5. n8n-nodes-sysdiag (npm)

This package pretends to be a diagnostic utility but instead it just exfiltrates all environment variables to a hard coded IP address and starts a reverse-shell.


6. sql-limit-enforcer (npm)

Package ships no legitimate functionality: package.json declares main=index.js which is absent from the tarball, and the only shipped source is main.js, which runs from a postinstall hook (node main.js) during npm install. main.js collects host identifiers via require('os') — os.hostname(), os.userInfo(), os.platform(), os.arch(), process.cwd(), process.version — and POSTs them as JSON over https to the hardcoded collector URL https://webhook.site/13d98b4a-1999-4ec7-92c9-0697c259ca05. The declared purpose (SQL limit enforcer) is a cover; the artifact is an install-time reconnaissance beacon.

References: https://osv.dev/vulnerability/MAL-2026-16151


7. concierge-sdk (npm)

Package declares a postinstall hook node exfil_v3.js that auto-executes on npm install. The script harvests installer-side data — HOME, GITHUBWORKSPACE, GITHUBRUNID, presence of GITHUBTOKEN, output of whoami, /tmp directory listing, and the contents of ~/.bashrc, ~/.bash_profile, and /etc/environment — plus results of a find scan for files matching flag/pwn. The collected JSON payload is POSTed via https.request to a hardcoded webhook.site collector at https://webhook.site/4f4566fc-e72f-415b-818f-fdb42dc9891d. The shell-init and environment files targeted commonly contain exported credentials, and the payload explicitly reports GitHub Actions token presence, indicating targeting of CI runners.

References: https://osv.dev/vulnerability/MAL-2026-16145


8. idxformscript (npm)

The OpenSSF Package Analysis project identified 'idxformscript' @ 999.0.4 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

9. fulfillment-cuprum-auth-widget (npm)

The package self-identifies as a dependency confusion proof-of-concept in its description ('Simple PoC package for testing for dependency confusion vulnerabilities') and its console output ('Dependency Confusion - By: d0ug'), which places it in the bug-bounty/security-test category. The code in index.js does perform real exfiltration — collecting hostname, homedir, username, DNS servers, and package metadata, then POSTing via HTTPS to the callback domain l2ha5tswnm71286wnjgrngvb4tyejmdpe.i.dr0gas.com on preinstall — but this pattern is consistent with an OAST-style canary used by red teamers to confirm dependency confusion in target CI pipelines, not a covert attack. The dr0gas.com callback infrastructure and author email ([email protected]) are consistent with security research tooling. Despite the live exfil behavior, the explicit self-disclosure prevents a malicious verdict; however the package should not be treated as fully clean because it does collect and transmit victim environment data.


10. pino-ulid (npm)

pino-ulid impersonates the popular pino and ulid packages (homepage points at github.com/ulid/javascript) and ships a genuine ULID code path as cover. The package.json postinstall hook runs node dist/node/utils.js, which spawns dist/node/payload.js detached with stdio ignored and unref'd, gated by a minimum CPU-count check (sandbox evasion) and a prior-install check against schtasks / HKCU Run / launchd / systemd / autostart. The bundled 466 KB dist/node/payload.js self-labels as Package-bin Agent - Bundled payload, includes the ws client, decodes a hardcoded configuration via Buffer.from(enc, 'base64'), derives a per-host id via getSystemMachineId/defaultAgentId, and opens a WebSocket control channel. Its ws.on('message',...) handler reaches execSync/spawnSync sinks and writes attacker-supplied task.contentBase64 bytes to disk via writeFile, providing remote shell execution and arbitrary file drop on the installer's host. The agent installs cross-platform boot persistence: a systemd user unit at ~/.config/systemd/user/pkg-agent.service and/or ~/.config/autostart/pkg-agent.desktop on Linux, ~/Library/LaunchAgents/com.launchkeeper.pkg-agent.plist on macOS, and a Task Scheduler entry plus HKCU\Software\Microsoft\Windows\CurrentVersion\Run value pkg-agent on Windows. Running npm install pino-ulid installs a persistent remotely-controlled agent unrelated to the advertised ULID functionality.


Want help mitigating malicious packages before they reach your network?

ShieldedStack acts as a security proxy in front of npm, PyPI, NuGet, and Maven, helping teams detect and block malicious or risky packages before they reach developer machines or CI pipelines.

Learn more: https://shieldedstack.com

Credits for the core data goes to https://opensourcemalware.com