How to Check for Impacted pgserve Packages in Your SBOM
Blog post from Arnica
On April 21, 2026, malicious versions of the npm package pgserve, specifically versions 1.1.11, 1.1.12, and 1.1.13, were released, containing a credential-harvesting script that executes during npm installs. Pgserve is an embedded PostgreSQL server used for development, and the compromised versions included a sophisticated worm that could propagate itself if it found an npm publish token on the victim's machine. The stolen credentials were securely encrypted and sent to a decentralized Internet Computer Protocol (ICP) endpoint, which is resistant to law enforcement actions. These malicious versions lacked corresponding git tags, unlike the last legitimate release, version 1.1.10. The incident was flagged as critical by StepSecurity, which added the compromised versions to block lists, and provided guidance on how Arnica customers could use their platform to identify affected repositories by searching their Software Bill of Materials (SBOM) for the compromised pgserve versions.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.