Embedded Malicious Code Affecting @forjacms/sections-react package, versions =1.8.4


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Attacked

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-FORJACMSSECTIONSREACT-17223224
  • published7 Jun 2026
  • disclosed6 Jun 2026
  • creditGuy Korolevski

Introduced: 6 Jun 2026

New Malicious CVE NOT AVAILABLE CWE-506  (opens in a new tab)

How to fix?

Avoid using all malicious instances of the @forjacms/sections-react package.

Overview

Affected versions of this package are vulnerable to Embedded Malicious Code containing a malicious binding.gyp file that drops and runs a self-propagating cloud secret stealer. The malicious code attempts to exfiltrate AWS, GCP, Azure, Vault, and Kubernetes credentials, as well as npm and RubyGems registry tokens, and GitHub Actions OIDC tokens.

The added package/index.js, containing the obfuscated payload, is called silently during npm install execution, without the use of postinstall scripts. This file is deliberately confused with the legitimate entry point dist/index.js, but is not itself an entrypoint.

References

CVSS Base Scores

version 4.0
version 3.1