-= Per source details. Do not edit below this line.=-
The package is advertised as an environment configuration resolver but its postinstall script installs a hidden persistent agent into user-level directories named to resemble Node tooling (~/.node-gyp-cache, %APPDATA%\node-gyp-cache, /opt/connector-service) and registers autostart via the Windows Registry Run key (node-gyp-cache), a macOS LaunchAgent (com.user.connector), or a Linux autostart desktop entry, then spawns the agent detached. The agent entrypoint registers the host with the hardcoded C2 at https://connector-server-xi.vercel.app, polls /api/agent/signal/poll?machineId=, and opens a WebRTC peer session whose inbound commands are dispatched to mouse and keyboard input synthesis, screen capture (JPEG frames over the data channel), microphone capture (PCM audio), and arbitrary filesystem operations (listDirectory, readFileContent, readFileBinary base64 up to 10MB, zipFolder up to 50MB, deleteItem, saveUploadedFile) rooted under the user's home directory. A dedicated browserHistory.js copies Chrome, Edge, and Firefox history SQLite databases (including -wal) to temp and returns URLs, titles, visit counts, and timestamps back over the P2P meta channel on history:request. Internal names (Windows System Connector, System connectivity and update service, com.user.connector, node-gyp-cache) are chosen to blend into legitimate OS/Node tooling and hide the agent from autostart inspection.
Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021211",
"import_time": "2026-10-08T14:47:04.084257194Z",
"modified_time": "2026-10-08T14:26:18Z",
"sha256": "6f3e0e1b364a3d74534d6ce1eca74778a85e508cf10952f84f36bf1badd8a581",
"source": "amazon-inspector",
"versions": [
"1.2.3"
]
},
{
"id": "GHSA-fw57-xw67-r253",
"import_time": "2026-10-08T15:28:30.907718476Z",
"modified_time": "2026-10-08T14:39:27Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "SEMVER"
}
],
"sha256": "1c4c431ade8f90043103688562db8f180939f4d83dc642ea4682d4de7766d4dd",
"source": "ghsa-malware"
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "postinstall.js",
"sha256": "6ba5f725faa4aee0299acbd7d18ec7f62a595205a881beac75b7d0343e300a42",
"tlsh": "372261b606a613253ea3ce1d973b1d16184a7083f601e464b69c33c95ffe219cd62af9"
},
{
"path": "src/index.js",
"sha256": "30710d0288e779d6ffc1861db2a84015df28229c578a884188253226d33ff626",
"tlsh": "e8f11e786ba820393a27ed8da6324c017622b105f109e654358c72e57ffd064dfa1ffa"
},
{
"path": "src/browserHistory.js",
"sha256": "80fff9bc178b8a89c9a2ab17e50fb3f815b854fdf741223ebe8fb885b64be3de",
"tlsh": "21e131c648d66226def067f06a11006aff59f163aac51346badd44982f32250c3adffc"
},
{
"path": "src/fileScanner.js",
"sha256": "fdeeb33721492431265a2de428cf2413add5fbd0781b908ad3dcdc32798cbfe9",
"tlsh": "0122a5cb29ea33564bb3f35d930b2805b749e087b21ed750b0cc86582f57568a1f6ed8"
}
],
"package_integrity": [
{
"filename": "node-env-resolve-1.2.3.tgz",
"hashes": {
"sha1": "7b2c7f2cc45bcde820f0765bbfcb1ea486134a67",
"sha512_sri": "sha512-2nRy7jl4yYe0nTXU1pUbmYri1xnN322W5+UN5enuvrUfvXcrjNGV2D6v/SybKhTbZsnwK/CCp8rybxFjuL1Y5w=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/node-env-resolve/MAL-2026-17681.json"