VDB
KO

MAL-2026-12183

Malicious code in nolimit-agent (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (9e9510731400dde41fd6705895d15e78bf4fe6f4560162a10bd6016e855f4221) The package tarball contains a hidden top-level directory `.ad/` populated with ~40+ heavily obfuscated JavaScript files (advanced-evasion.js, from-generator.js, phone-validator.js, proxy-validator.js, sms-providers.js, smtp-health-cache.js, socks-loader.js, web-command.js, and x0.js through xz.js). All files use hex-identifier obfuscation (`_0x`-prefixed symbols, single-line minified layout) consistent with javascript-obfuscator output designed to hide code behavior. The naming pattern (advanced-evasion, socks-loader, sms-providers, smtp-health-cache, phone-validator, web-command, proxy-validator) is aligned with SMS/SMTP/SOCKS abuse tooling — bulk-messaging, proxy-chained credential/SMS pumping, and evasion of anti-abuse controls. Placing these files in a dot-prefixed directory hides them from casual directory listings and package browsers. Obfuscation across every file in this directory, combined with the abuse-tooling module names, is inconsistent with a legitimate library and matches the shape of an operational abuse/attack toolkit distributed via npm.

## Source: ghsa-malware (3d95cf53ee52182a3a0cdb73309d759e4236cf56475edc44ec89e7c3e129bbf7) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / nolimit-agent
Introduced in: 0

No fixed version published yet for nolimit-agent (npm). Pin to a known-safe version or switch to an alternative.

References