top of page
perceptive_background_267k.jpg

pgserve Compromised on npm: Malicious Versions Harvest Credentials and Exfiltrate to a Decentralized ICP Canister

Published:

22 april 2026 om 02:01:07

Alert date:

22 april 2026 om 03:00:57

Source:

stepsecurity.io

Click to open the original link from this advisory

Supply Chain & Dependencies, Data Breach & Exfiltration, Database & Storage

On April 21, 2026, malicious versions of the pgserve npm package were published, affecting versions 1.1.11, 1.1.12, and 1.1.13. The package, which provides an embedded PostgreSQL server for development, was compromised with a 1,143-line credential-harvesting script that executes during npm install via postinstall hooks. The malicious code harvests credentials and exfiltrates them to a decentralized Internet Computer Protocol (ICP) canister. This supply chain attack targets Node.js developers using pgserve for database development, potentially compromising development environments and associated credentials. The attack demonstrates sophisticated use of decentralized infrastructure for data exfiltration, making detection and takedown more challenging.

Technical details

Mitigation steps:

Affected products:

pgserve
npm
Node.js
PostgreSQL

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page