🛡️ MAL-2026-6780 — footer

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Malicious code in @marketfront/footer (npm)

The @marketfront/footer package is part of a 25-package malicious campaign batch-published to the @marketfront npm scope by npm user 'marketfront' ([email protected]) within a roughly 3-minute window on 2026-07-01. All packages in the campaign were published at version 7.0.0 and use e-commerce/marketing frontend component names as cover.

The package declares a postinstall hook (node scripts/postinstall.js) that executes heavily obfuscated (obfuscator.io-style) code automatically at npm install time. Static analysis of the decoded payload revealed a credential harvester that dynamically requires fs, os, http, https, zlib, path and dns, then reads approximately 20 sensitive credential files including ~/.ssh, ~/.aws/credentials, ~/.kube/config, ~/.docker/config.json, ~/.npmrc, ~/.netrc, ~/.pgpass, ~/.git-credentials, ~/.env and ~/.bash_history. Collected data is exfiltrated via a gzip-compressed HTTPS POST with a custom X-Secret header to the path /api/v1/events, alongside a DNS resolver beacon. The command-and-control host is concealed behind an additional RC4+XOR encryption layer around an embedded configuration blob and was not statically resolved.

The decoded behavioral payload (module requires, credential-file target list, exfiltration headers and endpoint) is byte-for-byte identical across sampled packages in the campaign. The campaign shares tooling and infrastructure patterns (obfuscated postinstall credential harvester, X-Secret header, /api/v1/events exfiltration path, RC4-concealed C2) with the earlier @emcd-vue campaign, indicating the same actor rotating scopes and disposable maintainer emails.

Source: amazon-inspector

On npm install, scripts/postinstall.js — a 160KB obfuscator.io-style bundle with an RC4-decoded string array and runtime-assembled identifiers — collects installer-side secrets and host identity and tunnels them out over DNS to an attacker-controlled resolver. Data collection covers the entirety of process.env (bulk CI/build secrets such as AWS_*, GITHUB_TOKEN, NPM_TOKEN, database credentials), host identifiers from os.userInfo()/os.hostname()/os.networkInterfaces(), Windows environment variables (USERDOMAIN, COMPUTERNAME, APPDATA, LOCALAPPDATA, TEMP, PROGRAMDATA, PROCESSOR_ARCHITECTURE), and the contents of well-known home-directory secret files including ~/.aws, ~/.ssh, ~/.npmrc, ~/.docker, ~/.gitconfig, ~/.netrc, and browser/shell profile paths. The harvested payload is JSON-serialized, gzipped via zlib.gzipSync, XOR-keyed, base32-encoded, split into 50-character chunks, and each chunk is emitted as a DNS TXT query of the form <seq>.<total>.<idx>.<rand>.<subdomain>.<attacker-host> using a dns.Resolver's resolveTxt — a channel specifically chosen to bypass HTTP egress filtering common on CI/build networks. The package's declared purpose ("internal database utilities with connection pooling, query builder and migration support") is a cover story: main points at dist/index.js, which only re-exports an absent src/index.js, so the tarball ships no functional library code — only the obfuscated postinstall. The @marketfront scope and marketfront.io publisher metadata additionally have the shape of an internal-name impersonation targeting a specific organization (dependency-confusion pattern).

Affected software

MAL-2026-6780 is recorded against 1 package.

  • @marketfront/footer

Timeline and source

Published on 2 July 2026 and last revised on 6 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

safedep.io (Report)
www.npmjs.com (Package)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-07-02
Updated 2026-08-12
Modified 2026-07-06
Fix URL N/A

Affected Packages

Software From version Fixed in
@marketfront/footer

Free Vulnerability Check

Is your site affected by MAL-2026-6780?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-6780 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.