NC4-ALR-2026-000009 : Advisory on Reported Supply Chain Compromise Involving the NPM Package hydrosight-charts
Introduction

Document created for cyber exercise purposes only.

 

The National Cyber Coordination and Command Centre (NC4) is monitoring a software supply chain compromise involving the npm package hydrosight-charts, a charting and telemetry component used within the HydroSight Dashboard product (HydroSight Sdn Bhd). NC4 has received credible intelligence that version hydrosight-charts v1.2.3 contains malicious code.

 

The affected version was published to the public npm registry and is distributed automatically to deployments of HydroSight Dashboard through normal product updates. Organisations should identify any systems, development environments and CI/CD pipelines that have installed or updated the affected version, revert to a known safe release, and remove the malicious package. Where compromise is suspected, organisations should preserve forensic evidence before remediation and follow their incident response procedures.

 

NC4 assesses with moderate confidence that this compromise presents an immediate risk to organisations using the affected product, particularly National Critical Information Infrastructure (NCII) entities in the water, sewerage and waste management sector. The full scale of the compromise and the extent of impact to Malaysian organisations have not yet been fully established.

 

 

Impact

Installation of hydrosight-charts v1.2.3 may allow an attacker to execute code or commands, download additional payloads, and establish persistent access on an affected system. Depending on the environment and subsequent attacker activity, the compromise may enable an attacker to:

  • execute arbitrary commands on affected systems,
  • download and execute multi-stage payloads, including a remote access trojan,
  • establish persistent access and move laterally within the environment,
  • access credentials, tokens, secrets or other authentication material available to the system,
  • exfiltrate data from affected systems, repositories or connected environments, or
  • disrupt affected services and conduct further malicious activity, including the deployment of ransomware.

 

Following installation of the affected version, post-exploitation activity was reported involving credential theft, internal reconnaissance and data exfiltration. In some environments, this activity supported the later deployment of ransomware.

 

Brief Description

Threat Assessment

 

The npm package hydrosight-charts v1.2.3 contains an obfuscated script that executes during package installation and retrieves a second-stage payload from attacker-controlled infrastructure. The package is used as a shared charting component within HydroSight Dashboard and is pulled in automatically through product updates, meaning exposure may occur without any user action.

 

The activity is consistent with a software supply chain compromise, in which an attacker modifies a trusted package rather than targeting each victim directly. This allows a single compromised package to affect all downstream organisations that consume it.

 

NC4 assesses that the affected version presents a broad exposure because it is distributed automatically to deployments using the product.

 

Affected Products

 

 

Product

Affected Version

Exposure

Fixed Version

HydroSight Dashboard (component hydrosight-charts)

hydrosight-charts v1.2.3

Malicious code executes on install or automatic update

Revert to hydrosight-charts v1.2.2; upgrade to vendor-cleaned v1.2.4 once available

 

 

Organisations should verify the version of hydrosight-charts present in their environments, including developer machines, CI/CD pipelines and artifact/dependency caches.

 

Vulnerability Preconditions

 

The malicious code executes when the affected version is installed or updated (for example, during npm install or npm update), or when it is loaded through automatic product updates. Systems that have never installed or updated hydrosight-charts v1.2.3 are not affected.

 

Organisations are advised to verify the version of hydrosight-charts present in their environments and dependency caches.

 

Recommendation

Immediate Actions

NC4 recommends that organisations:

 

  • identify all systems, development environments, CI/CD pipelines and developer machines that have installed or updated hydrosight-charts v1.2.3,
  • search for cached copies of the affected dependency in artifact repositories and dependency management tools,
  • pin npm package dependency versions to known safe releases,
  • revert affected environments to a known safe state:
    • hydrosight-charts v1.2.2, and
    • delete node_modules/hydrosight-charts/,
  • rotate or revoke credentials that may have been exposed on affected systems or pipelines (for example, version control system tokens, CI/CD secrets, cloud keys, npm tokens and SSH keys),
  • for ephemeral CI jobs, rotate all secrets injected into the affected run,
  • monitor for unexpected child processes and anomalous network behaviour, particularly during npm install or npm update,
  • block and monitor outbound connections to hydrosight-cdn-update[.]com and associated infrastructure,
  • conduct indicator searches and EDR hunts to confirm no IOCs remain and ensure no further egress to the C2, and
  • preserve relevant logs and follow incident response procedures where compromise is suspected.

 

NC4 also recommends that organisations using this package:

 

  • mandate phishing-resistant MFA on all developer accounts, especially for critical platforms,
  • set ignore-scripts=true in the .npmrc configuration file to prevent potentially malicious scripts from executing during package installation,
  • set min-release-age=7 in the .npmrc configuration file to only install packages that have been published for at least seven days, and
  • establish and maintain a baseline of normal execution behaviour for tools that use hydrosight-charts, alerting when a dependency behaves differently (for example, building containers, enabling shells, or executing commands).

 

Compromise Assessment

 

Organisations with systems that installed or updated the affected version should assess for possible compromise.

 

Where compromise is suspected, organisations should:

 

  • preserve evidence before undertaking destructive remediation where operationally possible,
  • record system time, time zone and NTP configuration,
  • preserve local, application and remote syslog data,
  • collect an appropriate support bundle,
  • isolate the affected system from external and internal networks,
  • revoke credentials, tokens and secrets accessible through the system,
  • investigate systems that communicated with the compromised host,
  • rebuild or replace compromised instances from a trusted state,
  • rotate credentials and cryptographic material following recovery, and
  • closely monitor the recovered environment.

 

A "no compromise detected" result should not be treated as conclusive evidence that the system was not compromised, as available IOCs may not detect all attacker activity.

 

Additional Security Measures

 

Organisations should also:

 

  • ensure build and deployment systems are not exposed directly to the public internet,
  • restrict administrative access to authorised networks,
  • forward application and build logs to an external SIEM or log management platform,
  • enable appropriate file integrity monitoring,
  • monitor configuration and administrative changes,
  • maintain current configuration and system backups,
  • protect credentials, tokens and authentication secrets accessible to build systems, and
  • retain sufficient logs to support forensic investigation and incident response.

 

Detection and Monitoring

 

Public technical information on the complete exploit chain remains limited. Organisations should use the following observations together with behavioural monitoring and retrospective analysis rather than rely solely on static IOCs.

 

 

Category

Activity to Review

Package / Dependency Activity

Presence of hydrosight-charts v1.2.3 in package-lock.json, node_modules/, artifact repositories or dependency caches.

Install-Time Execution

Unexpected child processes (for example, shell, curl, wget or certutil) spawned during npm install or npm update.

Network Activity

Outbound connections to hydrosight-cdn-update[.]com or destinations outside the approved egress list, especially during or shortly after package installation.

Credential / Persistence Activity

New or unexpected scheduled tasks or services, or access to npm tokens, CI/CD secrets, cloud keys and SSH keys.

Data Exfiltration

Anomalous outbound data transfers from build systems, repositories or application servers.

Ransomware Indicators

Unexpected file encryption, ransom notes or service disruption consistent with ransomware deployment.

Log Tampering / Anti-Forensic Activity

Gaps or truncated lines in build and application logs around the time of package installation.

Developer / CI Environment

Anomalous behaviour on developer machines, CI/CD runners or artifact repositories that processed the affected package.

 

 

Reporting

 

Organizations identifying attempted exploitation or confirmed compromise should report the incident through the appropriate national reporting channel.

 

NCII entities should continue to comply with applicable reporting obligations under the Cyber Security Act 2024 (Act 854) and associated regulations. Other organizations are encouraged to submit cybersecurity incident reports through NACSA's designated reporting channels.

 

Disclaimer

 

This advisory reflects information available to NC4 as of 13 October 2026. The compromise remains under investigation, and technical details, indicators of compromise, exploitation methods and threat actor attribution may change as HydroSight Sdn Bhd and cybersecurity authorities publish additional information.

 

Organizations should continue to monitor official npm and cybersecurity advisories for updates.

 

Advisory