Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

@depro0x/despicable-menpm

Malicious code in @depro0x/despicable-me (npm) Remove it immediately and rotate any exposed credentials.

MAL-2026-873
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall @depro0x/despicable-me

What this malware does

The package @depro0x/despicable-me was found to contain malicious code.

The OpenSSF Package Analysis project identified '@depro0x/despicable-me' @ 11.0.0 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Malicious versions

7 flagged
6.0.08.0.09.0.011.0.013.0.014.0.016.0.0

Indicators of compromise (SHA-256)

6462180066b4c25e184d616993e44ba94d6e6fdf065db3e0e6ce52a1015a0aa0
408ee2d3c535747e02e11f32f8a20bafa12ddc1ac413c41dc80ed7375e926b02
e5e59fdbcd5eae4cddc95424e34ba5de09ae15fd2d265fcf832a68c4c4495a4a
4615e7677b737a414d7c43332b795fe84cb5d272e491befba14d42456ae28cfc
9d4f645b4e971818c96437326820425423bc5c41700995b66b0a6d96d110f145
cfd0bd7743a9548666d2cb6e0bbe7392bde2f52356f29403ba18b846c2f6c8d0
3fc28a0966ecc924884cf1cd6a75caf42b173878d6934a7f4774e294fba62ccd
0e512041534d296b22312d733434bb54944a4e026f6ddeaa493240cccc429ee9

Detection & response playbook

Malicious package
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for @depro0x/despicable-me (7 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging @depro0x/despicable-me across your stack and pipelines.

  2. If you installed it — respond

    Remove @depro0x/despicable-me from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If @depro0x/despicable-me was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks @depro0x/despicable-me before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. @depro0x/despicable-me on npm has been identified as a malicious package (versions 6.0.0, 8.0.0, 9.0.0, 11.0.0, 13.0.0, 14.0.0, 16.0.0 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Credits

  • Amazon Inspector · finder
  • OpenSSF: Package Analysis · finder

Detect & block this

O3 blocks @depro0x/despicable-me-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

@depro0x/despicable-me (npm) malicious package — MAL-2026-873 | O3 Security