Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

@finaxis/common-jsnpm

@finaxis/common-js is a confirmed malicious npm package (MAL-2026-14064) that steals credentials and exfiltrates sensitive data (malicious versions 0.3.4, 0.3.5, 0.3.6…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in @finaxis/common-js (npm)

MAL-2026-14064
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall @finaxis/common-js

What this malware does

Package publishes under a lodash-imitating identity: keywords lodash/lodash-js, and the README is a verbatim copy of the official lodash 4.18.1 README. The single shipped file dist/common-js.js is not lodash — it is a ~770 KB javascript-obfuscator bundle (17,969-entry rotated string array, _0xNNNN identifiers). After deobfuscation the bundle is a browser-based cryptocurrency-mining client: it opens a WebSocket to a caller/config-supplied pool URL, spawns a fan-out of Web Workers keyed by workerId, handles nonce framing, and bundles an AES-GCM decryption primitive (aesGcmDecrypt from @noble/ciphers) for pool message decryption. Wallet and worker identifiers are read from a config object with fallbacks (cfg.wallet||'x', cfg.worker||'worker'). A developer who installs this expecting a lodash-family utility and ships it in a web application will silently mine cryptocurrency on their end users' browsers, consuming visitor CPU/battery and creating a compliance/abuse liability for the downstream site. The identity masquerade (name/keywords/README all mimicking lodash) combined with heavy string-array obfuscation of the real payload is the standard shape of a supply-chain masquerade attack.

Malicious versions

5 flagged
0.3.40.3.50.3.60.3.80.3.10

Indicators of compromise (SHA-256)

f708a31239d3dc7490906a4a41f5ccb3cb76c99f89bc87b5ad5884939bb2d308
d3a81522907c6036250cd04caf2b6350ad1903fd50ed138cda550ec33a1a7ea0
832d1ce61ce1f1e1430c60e94175cc80700dfbb2f8d0f46fd7d00b64720026d8
858e186e40af34fa05e49209b9bfeb758f4b734da30dacd6bd66cdb5c77a368b
c6fdee952074aa29c57bde30ce12f536868aba1a38faf68a861d856e21cd7f36

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for @finaxis/common-js (5 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging @finaxis/common-js across your stack and pipelines.

  2. If you installed it — respond

    @finaxis/common-js is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If @finaxis/common-js was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks @finaxis/common-js before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. @finaxis/common-js on npm has been identified as a malicious package (versions 0.3.4, 0.3.5, 0.3.6, 0.3.8, 0.3.10 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-017968IN-MAL-2026-018266IN-MAL-2026-018268IN-MAL-2026-018267IN-MAL-2026-018265

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks @finaxis/common-js-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

@finaxis/common-js (npm) malicious package — MAL-2026-14064 | O3 Security