VYPR
Vypr IntelligenceAI-generatedOct 5, 2026

npm: 10 Malicious Packages, Many Using '-polyfill' Suffix, Disclosed in 7 Minutes

On October 5, 2026, ten malicious npm packages, many employing a shared '-polyfill' suffix, were disclosed within a tight seven-minute window.

Key findings

  • Ten malicious npm packages were disclosed on October 5, 2026.
  • All advisories were published within a tight seven-minute window.
  • Six packages shared a common '-polyfill' suffix, indicating a campaign signature.
  • Two packages, @inpeek/odata-angular and @inpeek/odata, shared a common @inpeek/ scope.
  • All disclosed packages were assigned a Critical severity rating.
  • Several packages were published just hours or days before their disclosure, suggesting fresh malicious uploads.

Coordinated npm Malicious Package Drop: Ten Packages Disclosed in Seven Minutes

On October 5, 2026, ten malicious packages were disclosed on the npm registry within a remarkably tight seven-minute window, from 18:34 UTC to 18:41 UTC. This rapid succession of advisories strongly indicates a coordinated takedown effort by security teams. The majority of these packages shared a common -polyfill suffix, pointing to a targeted campaign designed to distribute malicious code. This burst included newly published packages, such as @inpeek/odata, which was first published just nine hours before its disclosure, and @inpeek/odata-angular, published two days prior, highlighting the swift detection and removal of these threats.

The campaign exhibited clear patterns in package naming. Six of the ten disclosed packages utilized a shared -polyfill suffix, often combined with seemingly random alphanumeric strings, such as css-eqxcdx-polyfill, css-vvgsze-polyfill, css-nrmgzn-polyfill, css-kfvwax-polyfill, css-yhpodl-polyfill, and css-gwqyid-polyfill. This naming convention is a common tactic in malicious campaigns, aiming to blend in with legitimate utility packages or to create a large volume of similar-looking packages. Additionally, two packages, @inpeek/odata-angular and @inpeek/odata, shared the @inpeek/ npm scope, suggesting another distinct, albeit smaller, component of this coordinated drop. The remaining packages, with-cte and checkmate-remediation-assistant, while not fitting these specific naming patterns, were part of the same rapid disclosure event.

Details regarding the specific malicious behaviors of these packages were not immediately available in the provided advisories. However, the consistent "Critical" severity rating across all ten packages implies a significant threat to any system that installed them. Malicious packages in public registries often engage in activities such as credential harvesting, remote code execution, or the establishment of persistent backdoors. Without specific behavioral findings, the full scope of their intended impact remains to be detailed, but the critical severity underscores the potential for severe compromise.

All ten packages were assigned a Critical severity rating. This classification means that any computer or system that installed these malicious versions should be considered fully compromised. The implications are severe: sensitive data, including API keys, environment variables, and other credentials, could have been exfiltrated. Users are strongly advised to treat such systems as untrustworthy and to take immediate remediation steps. This includes rotating any sensitive credentials that may have been accessed from the compromised environment, ideally from a separate, secure machine.

Developers should immediately audit their package-lock.json, yarn.lock, or pnpm-lock.yaml files for the presence of any of the disclosed malicious packages. If any are found, the affected dependencies should be removed, and the environment should be thoroughly scanned for any lingering malicious artifacts. Given the critical nature of these compromises, it is prudent to assume a full system compromise and proceed with a comprehensive incident response plan. A representative list of package names to check for includes:

  • css-eqxcdx-polyfill
  • css-vvgsze-polyfill
  • @inpeek/odata-angular
  • with-cte
  • checkmate-remediation-assistant

Furthermore, organizations should review their npm token logs for any unauthorized publish events or suspicious activity that might indicate a compromised maintainer account, especially for packages that were newly published shortly before their disclosure.

This coordinated disclosure highlights the ongoing vigilance required to secure the software supply chain. While the specific actor behind this burst is not identified, the rapid deployment and subsequent takedown of multiple malicious packages within minutes underscore the dynamic nature of threats targeting public package registries. Such events are a stark reminder that even widely used ecosystems like npm are constant targets for malicious actors seeking to inject harmful code into the development pipeline.

AI-written article. Grounded in 0 CVE records listed below.