Your RSA-2048 keys break in 2030. Find every one of them before attackers do.See CBOMkit
@ncurran
The @ncurran scope on npm published 9 malicious packages. See the full package list, affected versions, and how to check whether your dependency tree pulled any of them in.
Malicious packages
9
Advisories
9
Ecosystem
npm
First seen
2026-06-18
What to do if you depend on any of these
Every package below was published as malicious under @ncurran. Treat any machine that installed one as compromised: remove the package and its lockfile entry, rotate every credential the build or runtime could reach (registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values) from a known-clean machine, and audit for unexpected outbound activity.
Because the packages share a publisher scope, a project that pulled in one has an elevated chance of having pulled in others. Search your lockfiles for @ncurran rather than checking a single package name.
All 9 packagesnpm
- @ncurran/dc-selftest-33afb7View advisory →
- @ncurran/dc-selftest-ba0ad4View advisory →
- @ncurran/sandbox-recon-7c4e1aView advisory →
- @ncurran/sandbox-recon-880538View advisory →
- @ncurran/sandbox-recon-9b2d4fView advisory →
- @ncurran/sandbox-recon-sys-5b2cView advisory →
- @ncurran/sandbox-recon-sys-5f1bView advisory →
- @ncurran/sandbox-recon-sys-6a3fView advisory →
- @ncurran/sandbox-recon-uac-4e7cView advisory →