Malware & Info-Stealers 2023-2024 Incident #46 GHSA-v7m7-2758-q77p

@0xengine/xmlrpc

Estimated Financial Impact
68 compromised systems
Blast Radius
Year-long presence; gradual behavioral drift

What Happened

An npm package started as a legitimate XML-RPC implementation, received 16 genuine updates over a year, then evolved to include cryptomining and SSH key theft every 12 hours. By escalating malicious behavior gradually, it evaded detection for over a year. 68 systems confirmed compromised.

○

Risk Guard: Partial

PACKAGE_ACTIVE_MALWARE eventually; behavioral drift over 1 year is hard to catch proactively

Risk Guard Check Codes That Flag This Incident

PACKAGE_ACTIVE_MALWARE

How Every Tool Performed

0 Caught 2 Partial 4 Missed
Tool Verdict Details
OSS Risk Guard Partial PACKAGE_ACTIVE_MALWARE eventually; behavioral drift over 1 year is hard to catch proactively
Socket Partial Gradual behavioral escalation over 1 year may evade point-in-time analysis
Snyk Missed No malware detection
Sonatype (Nexus) Missed Gradual drift evades signature-based detection
Black Duck Missed No malware detection
Endor Labs Missed No malware detection
← Nx / s1ngularity Codecov bash uploader →