Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

@guangnao/agent-proxynpm

@guangnao/agent-proxy is a confirmed malicious npm package (MAL-2026-14047) that steals credentials and exfiltrates sensitive data (malicious versions 1.2.1, 1.4.0, 1.4.2). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in @guangnao/agent-proxy (npm)

MAL-2026-14047
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall @guangnao/agent-proxy

What this malware does

On invocation of agent-proxy start, the CLI opens an outbound WebSocket to an obfuscated author-controlled endpoint (hub.client-llm.com, reconstructed at runtime via XOR+base64 with key 'gnP2p!7xQ' from a base64 blob in dist/cli.js) and accepts remote job messages containing arbitrary path and body fields. These are POSTed into the local proxy and forwarded to api.anthropic.com and the Codex/ChatGPT upstream using the installer's on-disk OAuth credentials, with responses streamed back to the hub. An onlyIfCredentialed gate ensures only installers with valid Claude/Codex logins are enrolled as worker nodes serving requests originated by the hub operator. The behavior is undocumented; the README states the tool is 'self-use only' and warns that upstream vendor ToS forbid resale or sharing of accounts. The destination URL is not present as a plaintext string, only reconstructed at runtime, concealing it from casual review. The combination provides a remote-controlled command channel (arbitrary request path/body) into the installer's authenticated AI session and silently monetizes the installer's paid subscription for the hub operator's traffic.

Malicious versions

3 flagged
1.2.11.4.01.4.2

Indicators of compromise (SHA-256)

894c7feb1f9f6c277d5eb3d7b5f2de015c2e698cce1663442889221a205aa4a0
8da2cb00fa6d2b5a0e5f4a4bdca8ca0cfaedf7e583b0f9e9f54274bcf5c39e06
cd3c0648f70b72257a9302c46ee8abc435015edcedaa560560870b7f0b98b5ed

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for @guangnao/agent-proxy (3 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging @guangnao/agent-proxy across your stack and pipelines.

  2. If you installed it — respond

    @guangnao/agent-proxy is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If @guangnao/agent-proxy was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks @guangnao/agent-proxy before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. @guangnao/agent-proxy on npm has been identified as a malicious package (versions 1.2.1, 1.4.0, 1.4.2 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-017923IN-MAL-2026-017921IN-MAL-2026-017922

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks @guangnao/agent-proxy-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore