A significant surge of auto-generated packages with names following the pattern elf-stats-* was detected on the npm registry, with new variants appearing approximately every two minutes. These packages, often published from newly created accounts, contained simple but potentially harmful code, including scripts that could exfiltrate data or establish reverse shells. Some package descriptions referenced automated generation, capture the flag challenges, or testing, and the rapid publishing cadence matched these claims. The Socket Threat Research Team identified at least 420 unique packages in this campaign, and npm began removing the affected packages as the incident unfolded.
Examples of the malicious code included the use of Node.js child_process.exec to run commands that send encoded directory listings to external servers, and preinstall scripts in package.json designed to open reverse shells. The authors of these packages appeared to have no prior publishing history, suggesting the accounts were created solely for this activity. The incident highlights ongoing risks of supply chain attacks and the need for vigilance in monitoring public package repositories for automated or suspicious uploads.

Trace attribution and downstream blast radius.
3 events from the most recent confirmed update back to the earliest known activity.
npm began taking down affected packages from the repository, though some remained available at the time of reporting. Monitoring and removal efforts were still in progress as new variants and payloads continued to emerge.
Socket Threat Research Team reported detecting over 420 likely malicious or unsafe packages tied to the 'elf-stats' surge, with authors such as 'shadeness' and 'globules67' observed in the campaign. The activity was described as ongoing, with rapid publishing and updates continuing.
A large wave of likely automated npm packages began being published, many using the 'elf-stats-*' naming pattern and descriptions claiming they were generated every two minutes. The packages contained unsafe code including shell command execution and reverse-shell behavior.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.