Supply-chain threat intelligence

Incident detail

criticalnpm·malware·github

Malicious code in redis-type-xyz (npm)

redis-type-xyz

Risk score

92

AI summary

Indexed incident for redis-type-xyz (npm).

Description

The redis-type-xyz package is an empty impersonation of Redis OM. It copies the redis-om-node repository, homepage, author, documentation, and declared dist/index.js entry point, but the published archive does not contain the declared dist directory or any usable implementation. Its dependency list replaces the legitimate ulid package used by Redis OM with ulid-xyz@^2.12.2.

Installing redis-type-xyz therefore installs the known-malicious ulid-xyz dependency. The ulid-xyz postinstall hook launches a detached background agent that decodes a WebSocket and HTTP C2 endpoint at 95.216.232.162:8010. The agent supports system information collection, drive and directory enumeration, removal, and deploy_binary tasks. deploy_binary writes attacker-supplied Base64 content to disk, registers persistence on Windows, macOS, or Linux, and launches the replacement agent. The malicious ulid-xyz dependency is independently tracked as MAL-2026-6672. redis-type-xyz is a separate delivery package that intentionally substitutes the known-malicious dependency into an otherwise copied Redis OM manifest.


Credit: OpenSSF (source)

Technical details

Indicators

  • ghsa
    95%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents