Attacker Impact
A malicious npm package version in this campaign can execute during dependency installation through the node-gyp build path. Public research reported credential harvesting and self-propagation behavior across dozens of packages, so affected installs should be treated as supply-chain compromise evidence rather than a normal dependency vulnerability.
Root Cause
The campaign relied on package metadata and build-file behavior that can run during installation even when the package does not declare a normal lifecycle script. That makes repository manifests, lockfiles, and committed build files useful places to look for exposure without running the package.
Concrete Fixes
- Remove or replace any affected package version and regenerate the active npm, pnpm, or Yarn lockfile from trusted registry state.
- Remove any unexpected node-gyp build-file execution artifact from owned source after reviewing adjacent loader files as text only.
- Clear dependency caches, rebuild CI images, devcontainers, Docker layers, and deployment artifacts that may have installed the package.
- Rotate npm, GitHub, cloud, SSH, deployment, and CI credentials that were available to environments where the package may have installed.
- Verify through dependency-tree, lockfile, source review, and clean build artifacts. Do not execute affected packages or build scripts for proof.
Covered by FixVibe
FixVibe's GitHub repo scans flag repositories whose manifests or lockfiles resolve known malicious npm package versions from this campaign, or whose source contains the node-gyp build-file execution pattern described in public campaign research [S1], [S2], [S3]. If a finding appears, remove the affected dependency or source artifact, rebuild install caches and CI images, and rotate credentials that may have been available during installation.
