A malicious npm package named fezbox was published to npm in August 2025 and remained available for 32 days before npm seized it in September. Investigators found that versions 1.0.0 through 1.3.0 used a postinstall payload with a 120-second delay and environment checks, then retrieved a QR code from Huawei Cloud infrastructure and decoded it into Base64-encoded JavaScript. The payload was designed to steal browser cookies, origin, and user-agent data and exfiltrate host reconnaissance to attacker-controlled endpoints, including an unauthenticated /collect endpoint and a secondary Railway.app service used for structured credential collection.

Trace attribution and downstream blast radius.
6 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-03, Breakglass assessed the operation as likely run by a China-based low-to-medium sophistication actor. The assessment was based on Huawei Cloud hosting in Beijing, China Mobile source IP usage, Chinese-locale artifacts, and the operator's poor operational security.
By 2026-04-03, researchers reported that the Huawei Cloud server at 1.94.210.59 remained online with unauthenticated endpoints such as /collect and /data. Analysis linked the infrastructure to fezbox and a QR-code-delivered browser cookie stealer, with four exposed exfiltration records visible.
npm security removed or seized the malicious fezbox package on 2025-09-22, ending its availability after 32 days on the registry. No confirmed third-party victim data was identified in the exposed primary database at the time described by investigators.
Exposed exfiltration records showed multiple apparent self-test submissions from the operator's own machine rather than confirmed external victims. The data included hostname, username, OS, hardware, working directory, and an IP linked to China Mobile in Nanjing, Jiangsu Province, China.
For 32 days after publication, fezbox remained available on npm and reached up to 476 downloads while communicating with Huawei Cloud-hosted infrastructure. The malware performed host reconnaissance, delayed execution, fetched a QR code containing Base64-encoded JavaScript, and attempted to exfiltrate data to unauthenticated endpoints.
The malicious npm package fezbox was published on npm on 2025-08-21. Versions 1.0.0 through 1.3.0 used a postinstall mechanism tied to attacker-controlled infrastructure and QR-code-delivered JavaScript.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
intel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourcenpmjs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.