Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

@ably-forks/crypto-jsnpm

@ably-forks/crypto-js is a confirmed malicious npm package (MAL-2024-2033) that executes malicious code on install (malicious version 3.999.0). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in @ably-forks/crypto-js (npm)

MAL-2024-2033
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall @ably-forks/crypto-js

Malicious versions

1 flagged
3.999.0

Indicators of compromise (SHA-256)

a8df0ae4fdd0987d41395863dadb5a706feb1c18ff59b8f753241a18ee7aaf98
11dd5dad99b92652f72ffd891888e600b09f5ba66d7fa99cb87b64e31313e5c4
4179980dc8b4da1a0d6481754d4f6653b18a8310f7488ae8ebd63b37a1d1e669
134a93c7feda70af10f7bd6587890b8086541df596acb9cb775e969836bc52fe

Detection & response playbook

Malicious package
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for @ably-forks/crypto-js (version 3.999.0). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging @ably-forks/crypto-js across your stack and pipelines.

  2. If you installed it — respond

    Remove @ably-forks/crypto-js from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If @ably-forks/crypto-js was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks @ably-forks/crypto-js before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. @ably-forks/crypto-js on npm has been identified as a malicious package (version 3.999.0 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

RLMA-2024-00004RLUA-2024-05856RLUA-2026-05791

References

Credits

  • ReversingLabs · finder

Detect & block this

O3 blocks @ably-forks/crypto-js-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore