nottuff7@1.7.7
Malicious code in nottuff7 (npm)
Analysis
This package is one of roughly ninety-five coordinated, mass-published npm names that all ship the same browser-based web-proxy payload as a static site, abusing public npm CDNs (unpkg/jsdelivr) as the delivery channel so users can reach a web-filter-bypass proxy through registry-CDN hostnames rather than via npm install. The declared entry point is a browser ServiceWorker (sw.js) with no Node lifecycle hooks, so installing or requiring the package executes nothing on a developer machine; the malicious behaviour runs only when the bundled assets are loaded in a browser. The ServiceWorker injects a script into proxied pages that forces new-tab navigations, and the cover page (a decoy tutoring landing page) runs inline code that, on the first user click, keypress, or touch, opens a pop-under window to an external ad URL (hxxps://abdct[.]com/) gated by a fifteen-minute localStorage cooldown, and additionally loads a remote third-party script. The package also bundles a shell script (auto-publish.sh) that iterates a hardcoded list of package names and force-publishes each to npm, documenting the deliberate registry-pollution / ad-monetization intent.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 08:19 PM
- analyzed
- Jun 16, 2026, 08:29 PM
Related advisories
- nottuff15@1.7.7
- tronweb-crypto@6.3.1
- chai-plugin-kit@5.8.1
- nat-ulid@3.0.2
- yellow-discord-lookup-v1@1.0.3
- winston-prism@1.0.1
- webpack-patch@1.1.7
- web3logger@1.1.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.