What is CWE-506?
The product contains code that appears to be malicious in nature.
Malicious flaws have acquired colorful names, including Trojan horse, trapdoor, timebomb, and logic-bomb. A developer might insert malicious code with the intent to subvert the security of a product or its host system at some time in the future. It generally refers to a program that performs a useful service but exploits rights of the program's user in a way the user does not intend.
CWE-506 is a class-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific.
Source: MITRE CWE (CWE-506 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Confidentiality, Integrity, Availability — Execute Unauthorized Code or Commands
Source: MITRE CWE, common consequences.
How CWE-506 is exploited in the wild
Threadlinqs maps 9 CVEs to CWE-506, published between 2024-03-29 and 2026-09-24. 5 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 2 are tied to ransomware campaigns. By CVSS v3 severity the set splits into 4 critical, 4 high. The highest EPSS score in the set is 91.3% (CVE-2025-30066), the modelled probability of exploitation in the next 30 days. 356 tracked threats reference CWE-506 directly or through a CVE it covers; the most recent is “MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealer” (2026-09-30). Affected products concentrate in @tanstack (1), Aquasec (1), Litellm (1), among 10 vendors in total.
Vulnerabilities (CVEs)
All 9 CVEs mapped to CWE-506, CISA KEV first, then by CVSS score.
- CVE-2026-48027 — CISA KEV · CVSS 9.8 critical · EPSS 26.8% · published 2026-05-27
- CVE-2026-45321 — CISA KEV · CVSS 9.6 critical · EPSS 15.0% · published 2026-05-12
- CVE-2026-33634 — CISA KEV · CVSS 8.8 high · EPSS 21.1% · published 2026-03-23
- CVE-2025-30066 — CISA KEV · CVSS 8.6 high · EPSS 91.3% · published 2025-03-15
- CVE-2025-30154 — CISA KEV · CVSS 8.6 high · EPSS 15.3% · published 2025-03-19
- CVE-2024-3094 — CVSS 10 critical · EPSS 84.9% · published 2024-03-29
- CVE-2026-97230 — CVSS 9.8 critical · EPSS 0.2% · published 2026-09-24
- CVE-2026-67595 — CVSS 8.1 high · EPSS 0.4% · published 2026-07-29
- CVE-2026-48161 — EPSS 0.4% · published 2026-08-10
Affected vendors
- @tanstack — 1 CVE
- Aquasec — 1 CVE
- Litellm — 1 CVE
- Nx — 1 CVE
- Reviewdog — 1 CVE
- Telnyx — 1 CVE
- Tj-actions — 1 CVE
- Tukaani — 1 CVE
- dai-shi — 1 CVE
- webreinvent — 1 CVE
Threat activity
356 tracked threats cite CWE-506; the 25 most recent are listed.
- MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealerHIGH
- Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)HIGH
- PhantomSub: 101 Malicious npm Baileys Forks Force Developers' WhatsApp Accounts into Attacker-Controlled Groups/ChannelsMEDIUM
- Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)HIGH
- Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm PackagesHIGH
- DPRK-Linked Graphalgo Campaign Abuses HashiCorp Terraform Registry with Malicious Providers and Go Modules to Deliver Go RAT with Slack and Arbitrum Sepolia Blockchain C2HIGH
- Rust Team Members and Popular Crate Owners Targeted via Fake Job Video Calls (North Korea-Linked)HIGH
- GHAPPIER Loader: npm Trusted-Publishing Abuse Compromises @dforge-core/dforge-mcpHIGH
- indexed-btree npm Campaign: Runtime-Triggered Loader Evades Install-Script Defenses via BTree.prototype.set()HIGH
- North Korean WaterPlum (Contagious Interview) Hackers Target IT Professionals with BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, StoatWaffle MalwareHIGH
- PhantomRaven: LLM-Generated npm Information Stealer Used for Bug Bounty HuntingHIGH
- Admin Menu Editor Pro WordPress Plugin Backdoored via Supply-Chain Compromise, 1,500 Sites AffectedCRITICAL
- SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent BackdoorCRITICAL
- ChainDrop/Mini Shai-Hulud npm Worm Compromises keyv, cacheable, and 400+ Downstream Packages via Ethereum-Resolved C2CRITICAL
- Shai-Hulud npm Supply-Chain Worm: Two Alleged TeamPCP Members Charged by AFP/FBICRITICAL
- npm Supply-Chain Compromise: @7nohe/openapi-react-query-codegen Ships "Trinitite" Credential-Harvesting WormCRITICAL
- 24 Malicious npm Packages Abuse Registry Mirrors as Phishing Infrastructure (Fake Cloudflare/Microsoft Login Pages)MEDIUM
- GitHub Actions Supply Chain Attack: tj-actions & reviewdog Compromise (CVE-2025-30066, CVE-2025-30154)CRITICAL
- Sophos X-Ops: Attackers Impersonate Claude, ChatGPT, Copilot and Perplexity to Distribute Infostealers, Backdoors and Malicious Browser ExtensionsHIGH
- 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2CRITICAL
- SDLC Supply Chain Attacks: ChainDrop npm Worm and Developer Pipeline TargetingHIGH
- Popular Rust Packages With 244M Downloads Compromised in Supply Chain AttackCRITICAL
- Popular Rust Crates arrayref, internment, append-only-vec Compromised in Build-Time Supply Chain Attack via proc-macro1 Typosquat (DPRK/Sapphire Sleet)CRITICAL
- SilkParasite: China-Nexus APT Deploys Seven RAT Families Against Central Asian GovernmentsHIGH
- Operation ASTERIX: AI-Assisted Crypto Wallet Phishing/Vishing Fraud Pipeline Abuses Claude Code and KimiHIGH
Mitigations
- Testing: Remove the malicious code and start an effort to ensure that no more malicious code exists. This may require a detailed review of all code, as it is possible to hide a serious attack in only one or two lines of code. These lines may be located almost anywhere in an application and may have been intentionally obfuscated by the attacker.
Source: MITRE CWE, potential mitigations.
Detection methods (MITRE CWE)
- Manual Static Analysis - Binary or Bytecode (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Binary / Bytecode disassembler - then use manual analysis for vulnerabilities & anomalies Generated Code Inspection
- Dynamic Analysis with Manual Results Interpretation (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Automated Monitored Execution
- Manual Static Analysis - Source Code (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Manual Source Code Review (not inspections)
- Automated Static Analysis (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Origin Analysis
Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.