Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. @opensearch-project/opensearch
  4. ›
  5. GHSA-27f5-xjrr-q9ff

GHSA-27f5-xjrr-q9ff: Malware in @opensearch-project/opensearch

May 19, 2026

Overview

The OpenSearch Project has sustained a security incident involving an external actor gaining force-push permissions within the project’s CI infrastructure to embed malicious packages into four release versions of @opensearch-project/opensearch. Users are instructed to immediately take actions recommended in the Remediation section of this advisory.

Affected Versions

Package: @opensearch-project/opensearch

VersionPublished (UTC)Published (America/New_York)
3.5.32026-05-12T00:47:39ZMay 11, 2026, 8:47:39 PM EDT
3.6.22026-05-12T00:29:34ZMay 11, 2026, 8:29:34 PM EDT
3.7.02026-05-12T00:42:29ZMay 11, 2026, 8:42:29 PM EDT
3.8.02026-05-12T00:43:54ZMay 11, 2026, 8:43:54 PM EDT

Remediation

Any computer that has these package versions installed or updated between 00:00 UTC 12 May 2026 (8:00 PM EDT 11 May 2026) and 10:00 UTC 12 May 2026 (6:00 AM EDT 12 May 2026) should be considered fully compromised. Steps should immediately be taken to prevent further compromise.

  • All secrets and keys stored on that computer should be rotated immediately from an alternate system.
  • The affected packages should be removed immediately, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

References

GHSA-g7cv-rxg3-hmpx https://github.com/TanStack/router/issues/7383

References

  • github.com/advisories/GHSA-27f5-xjrr-q9ff
  • github.com/opensearch-project/opensearch-js/security/advisories/GHSA-27f5-xjrr-q9ff

Code Behaviors & Features

Detect and mitigate GHSA-27f5-xjrr-q9ff with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

Version 3.5.3, version 3.6.2, version 3.7.0, version 3.8.0

Solution

Unfortunately, there is no solution available yet.

Impact 9.6 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-506: Embedded Malicious Code

Source file

npm/@opensearch-project/opensearch/GHSA-27f5-xjrr-q9ff.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 23 Jun 2026 12:24:25 +0000.