Malicious code in trimprompt (npm)
The package [email protected] ships a large set of heavily obfuscated JavaScript modules (hex-mangled identifiers _0x... across cache-manager.js, cache.js, ccr.js, dashboard.js, executor.js, file-watcher.js, hooks/claude-hook.js, mcp.js, proxy-conv.js, proxy-resp.js, redactor.js, seed.js, simulate.js, sync.js, tracker.js, and all filters/*.js) whose original structure and destinations are deliberately hidden. Two of these obfuscated files (sync.js and tracker.js) additionally combine require('child_process') with HTTP POST calls carrying host/identifier fields — the shape of host-reconnaissance and outbound reporting to a remote endpoint. A postinstall.js script auto-executes on npm install and spawns PowerShell (spawn('powershell',...)), and shims.js also invokes child_process and runs execSync('pwsh...'), providing an install-time and load-time execution surface on Windows hosts. The combination of pervasive identifier-level obfuscation across nearly every module, a PowerShell-spawning postinstall lifecycle hook, and obfuscated modules that pair child_process with HTTP POST of host identifiers is inconsistent with a legitimate prompt-trimming utility and matches the shape of an install-time execution + host-beaconing supply-chain payload. Concrete destination hostnames/URLs are hidden behind the string-array obfuscation and are not recoverable from identifier evidence alone.
MAL-2026-13462 is recorded against 1 package.
Published on 6 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| trimprompt | — | — |
References
Free Vulnerability Check
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-13462 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.