Supply chain · npm · High
Critical npm Package 'statist-browser-typed-client-eventea.projects.pwakasko' Compromises Systems
Threat Engine Auto-Feed · data current as of 2026-08-09
A critical malicious npm package, 'statist-browser-typed-client-eventea.projects.pwakasko', has been identified. Installation of this package leads to full system compromise, necessitating immediate action to protect secrets and remediate affected systems.
- Package: npm / statist-browser-typed-client-eventea.projects.pwakasko
- Affected versions: >= 0
- Severity: critical
- Reach: ~224/wk
- Exposure: 70/100 (High)
What happened — Credential / secret theft
The npm package 'statist-browser-typed-client-eventea.projects.pwakasko' contains malware. Any system that has installed or run this package is considered fully compromised, indicating an attacker has gained unauthorized access and control.
How the attack works
This is a malicious package attack where a seemingly legitimate software component introduces harmful code into a development or production environment. Upon installation, the malware executes, establishing persistence and granting an attacker full control over the compromised system, likely enabling credential and secret theft.
Who's exposed
Profiles most at risk
- Development teams using npm
- Organizations with CI/CD pipelines that pull npm packages
- Any system administrator or developer who has installed this specific package
Conditions that increase exposure
- Unpinned dependencies that automatically pull the latest versions of packages
- Lack of package lockfiles (e.g., package-lock.json) to ensure consistent dependency versions
- Use of internal package mirrors that may not have been updated with advisory information
Blast-radius scenarios
- An attacker gains full control over the compromised system, potentially leading to data exfiltration, further network penetration, or deployment of additional malicious software.
- All secrets and keys stored on the compromised computer are exposed and can be stolen by the attacker, leading to broader credential compromise across an organization.
What to do (defensive)
Detect
- Identify all systems where 'statist-browser-typed-client-eventea.projects.pwakasko' (any version) may have been installed or run.
- Review dependency trees in projects for the presence of this package.
Contain
- Immediately isolate any identified compromised systems from the network to prevent further lateral movement or data exfiltration.
- Do not rely on the compromised system for remediation; assume it is untrustworthy.
Remediate
- Consider all secrets and keys stored on compromised systems to be compromised; rotate them immediately from a different, trusted computer.
- Remove the malicious package; however, be aware that full control may have been given to an outside entity, and removal alone may not eliminate all malicious software.
- Rebuild compromised systems from trusted images or backups after ensuring the malicious package is no longer present in the build process.
Frontier verdict — High
This is a critical severity incident requiring immediate isolation of affected systems and comprehensive secret rotation due to full system compromise.
Sources
For detection-engineering and awareness only · point-in-time · not security advice · sourced from the GitHub Advisory Database.