


Perceptive Security
SOC/SIEM Consultancy

pgserve Compromised on npm: Malicious Versions Harvest Credentials and Exfiltrate to a Decentralized ICP Canister
Published:
22 april 2026 om 02:01:07
Alert date:
22 april 2026 om 03:00:57
Source:
stepsecurity.io
Supply Chain & Dependencies, Data Breach & Exfiltration, Database & Storage
On April 21, 2026, malicious versions of the pgserve npm package were published, affecting versions 1.1.11, 1.1.12, and 1.1.13. The package, which provides an embedded PostgreSQL server for development, was compromised with a 1,143-line credential-harvesting script that executes during npm install via postinstall hooks. The malicious code harvests credentials and exfiltrates them to a decentralized Internet Computer Protocol (ICP) canister. This supply chain attack targets Node.js developers using pgserve for database development, potentially compromising development environments and associated credentials. The attack demonstrates sophisticated use of decentralized infrastructure for data exfiltration, making detection and takedown more challenging.
Technical details
Mitigation steps:
Affected products:
pgserve
npm
Node.js
PostgreSQL
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
