Home / Companies / Arnica / Blog / Post Details
Content Deep Dive

How to Check for Impacted pgserve Packages in Your SBOM

Blog post from Arnica

Post Details
Company
Date Published
Author
Arnica
Word Count
491
Company Posts That Month
2
Language
English
Hacker News Points
-
Post removed?
No
Summary

On April 21, 2026, malicious versions of the npm package pgserve, specifically versions 1.1.11, 1.1.12, and 1.1.13, were released, containing a credential-harvesting script that executes during npm installs. Pgserve is an embedded PostgreSQL server used for development, and the compromised versions included a sophisticated worm that could propagate itself if it found an npm publish token on the victim's machine. The stolen credentials were securely encrypted and sent to a decentralized Internet Computer Protocol (ICP) endpoint, which is resistant to law enforcement actions. These malicious versions lacked corresponding git tags, unlike the last legitimate release, version 1.1.10. The incident was flagged as critical by StepSecurity, which added the compromised versions to block lists, and provided guidance on how Arnica customers could use their platform to identify affected repositories by searching their Software Bill of Materials (SBOM) for the compromised pgserve versions.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.