Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

@demica/sharednpm

Malicious code in @demica/shared (npm) Remove it immediately and rotate any exposed credentials.

MAL-2026-5351
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall @demica/shared

What this malware does

Note: This report is updated by a verification record

Dep-confusion squat of internal @demica/shared at sentinel high version 99.99.100 + auto-exec postinstall (canary.js) beaconing to RAW IP 157.230.17.236:80/dc. Sentinel-high-version + auto-exec beacon = MALICIOUS per operator policy (c913); "authorized canary" framing does NOT downgrade, raw-IP dest matches masterkrweb. 6-pkg @demica canary campaign.

On install, the package's postinstall hook (node canary.js postinstall per package.json) issues an unconditional HTTP GET to bare IP 157.230.17.236:80 at path /dc with query params containing the package name, version, a nonce, and the lifecycle phase. No environment variables, filesystem contents, or credentials are read or transmitted; the payload is limited to package metadata. The README describes this as an authorized dependency-confusion canary against the @demica scope. The fact-of-install ping is otherwise benign, but it performs unconsented outbound network at install time, the destination is a bare IP over cleartext HTTP with no authentication or pinning, and the same postinstall hook is a position from which a future republish could deliver arbitrary payloads. Routing to human review so the @demica organization can confirm the canary is theirs and that the destination IP is operator-controlled.

Malicious versions

2 flagged
99.99.9999.99.100

Indicators of compromise (SHA-256)

dfc020ab633bac129072df0d74deea8e0a2e118b43dbebf01ba9bbf2b13b6e76
becb5aca9f28fbd99a4f45ed70489960879ba81cfbd2071648c98cf5e867d8f9

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for @demica/shared (2 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging @demica/shared across your stack and pipelines.

  2. If you installed it — respond

    @demica/shared is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If @demica/shared was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks @demica/shared before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. @demica/shared on npm has been identified as a malicious package (versions 99.99.99, 99.99.100 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-005010IN-MAL-2026-008112

References

Credits

  • Amazon Inspector · finder
  • SafeDep · finder

Detect & block this

O3 blocks @demica/shared-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.