Junglewise Threat Intelligence

OpenSearch Project opensearch-js embedded malicious code

Severity: critical · CVSS 9.6 · Published 2026-05-19

Vendors: OpenSearch Project.

Executive brief

The OpenSearch Project's software distribution system was compromised by an external actor who embedded malicious code into several versions of the official OpenSearch JavaScript client. Any system that installed or updated this library during the infection window should be considered fully compromised, potentially allowing attackers to steal sensitive data, credentials, and encryption keys. Organizations using this library must immediately rotate all secrets and investigate affected systems for persistent unauthorized access.

Technical details

This is a supply chain attack (CWE-506) resulting from an external actor gaining unauthorized force-push permissions within the OpenSearch Project's CI infrastructure. The attacker injected malicious code into npm package versions 3.5.3, 3.6.2, 3.7.0, and 3.8.0. Exploitation occurs automatically upon installation or update of the affected library, potentially granting the attacker full remote control over the host system. The vulnerability is characterized by a CVSS score of 9.6, reflecting high impact on confidentiality, integrity, and availability with a network-based attack vector. Users are advised to rotate all credentials stored on affected machines and remove the compromised packages.

Affected products

  • OpenSearch Project @opensearch-project/opensearch 3.5.3, 3.6.2, 3.7.0, 3.8.0

Timeline

  • 2026-05-12: other: Start of infection window
  • 2026-05-12: other: End of infection window
  • 2026-05-12: disclosed: Initial advisory publication
  • 2026-05-19: advisory: GitHub Advisory Database entry reviewed

References

Related threats