Supply chain · npm · High

CRITICAL: Malicious npm package 'statist-browser-typed-client-mb.product.analytics' compromises systems

Threat Engine Auto-Feed · data current as of 2026-08-25

A critical vulnerability has been identified in the npm package 'statist-browser-typed-client-mb.product.analytics', which is confirmed malware. Any system where this package was installed or run should be considered fully compromised, necessitating immediate secret rotation and thorough remediation.

  • Package: npm / statist-browser-typed-client-mb.product.analytics
  • Affected versions: >= 0
  • Severity: critical
  • Reach: ~25/wk
  • Exposure: 60/100 (High)

What happened — Credential / secret theft

The npm package 'statist-browser-typed-client-mb.product.analytics' has been identified as malicious software. Installation or execution of this package leads to a full compromise of the host system.

How the attack works

This attack involves a malicious software package being introduced into a software supply chain. When a developer or automated system installs or runs the compromised package, it executes unauthorized code, leading to system compromise and potential data exfiltration or persistent access for an attacker.

Who's exposed

Profiles most at risk

  • Development teams using npm for package management
  • Organizations with CI/CD pipelines that pull npm packages
  • Any user or system that has directly or indirectly installed 'statist-browser-typed-client-mb.product.analytics'

Conditions that increase exposure

  • Unpinned dependencies that allow automatic updates to malicious versions
  • Lack of package lockfiles (e.g., package-lock.json) to ensure consistent dependency versions
  • Use of internal package mirrors that may not vet packages for malicious content
  • Automated build processes that install dependencies without manual review

Blast-radius scenarios

  • An attacker gains full control over the compromised computer, potentially leading to credential theft, data exfiltration, or further network penetration.
  • All secrets and keys stored on the compromised machine are exposed and can be used by an attacker.
  • The compromised system could be used as a pivot point for lateral movement within an organization's network.

What to do (defensive)

Detect

  • Review package dependency lists (e.g., package.json) for 'statist-browser-typed-client-mb.product.analytics'.
  • Scan build logs and CI/CD pipeline outputs for evidence of 'statist-browser-typed-client-mb.product.analytics' being installed.
  • Monitor network traffic for unusual outbound connections from systems that may have installed the package.

Contain

  • Immediately isolate any systems identified as having installed or run 'statist-browser-typed-client-mb.product.analytics' from the network.
  • Suspend any CI/CD pipelines or automated processes that may be installing this package.
  • Block 'statist-browser-typed-client-mb.product.analytics' in your package registry or proxy to prevent further installations.

Remediate

  • Consider any computer that installed or ran 'statist-browser-typed-client-mb.product.analytics' to be fully compromised and rebuild it from a trusted image.
  • Rotate all secrets and keys (e.g., API keys, SSH keys, passwords) that were stored on or accessible from the compromised computer, using a different, trusted system.
  • Thoroughly audit all systems for persistence mechanisms that may have been installed by the attacker, as simply removing the package may not fully remediate the compromise.

Frontier verdict — High

Prioritize immediate investigation and remediation for any system that installed 'statist-browser-typed-client-mb.product.analytics' due to critical system compromise risk.

Sources

For detection-engineering and awareness only · point-in-time · not security advice · sourced from the GitHub Advisory Database.