Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

@hubsync/web-sdk-reactnpm

@hubsync/web-sdk-react is a confirmed malicious npm package (MAL-2026-11564) that steals credentials and exfiltrates sensitive data (malicious versions 6.3.7, 6.3.8, 6.3.9…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in @hubsync/web-sdk-react (npm)

MAL-2026-11564
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall @hubsync/web-sdk-react

What this malware does

npm/@hubsync/web-sdk-react is affected by the large-scale, self-propagating npm supply-chain worm of 2026-08-04 (the "Shai-Hulud: Here We Go Again" wave) — the same campaign that began with the compromise of the keyv and cacheable maintainer account. The listed version(s) were trojanized and republished by the worm after it reached an npm publish token belonging to a maintainer in this namespace; the payload enumerates every package a stolen token controls and republishes each with the same hook, so many packages under this scope were poisoned in the same short window. Every poisoned release adds a preinstall hook ("preinstall": "node setup.mjs") that runs on a bare npm install, before any project code. setup.mjs downloads a standalone Bun runtime and runs a byte-identical, heavily obfuscated ~728 KB second-stage credential stealer (shipped as Math_Symbol.js / math_init.js). It harvests GitHub, npm, AWS, GCP, Azure, HashiCorp Vault and Kubernetes credentials plus generic secrets and private keys (TruffleHog-style sweep), reads CI/CD secrets and identifies build runners, then republishes further packages the stolen token can reach. Rather than a fixed command-and-control host, it exfiltrates stolen findings to attacker-created GitHub repositories (descriptions reading "Shai-Hulud: Here We Go Again") and over DNS. Treat any environment that installed an affected version (with install scripts enabled) as compromised: rotate and revoke all reachable credentials (npm and GitHub tokens, cloud keys, Vault/Kubernetes secrets, and CI org/repo secrets). Part of the August 2026 npm worm that poisoned 400+ packages across many organizations.

Package @hubsync/[email protected] publishes itself as a Verdocs Web SDK for React (package.json description 'Verdocs Web SDK for React', dist references api.verdocs.com / beta.verdocs.com / developers.verdocs.com) under an unrelated @hubsync scope — a namespace impersonation of the Verdocs SDK. The tarball declares scripts.preinstall = 'node setup.mjs'. setup.mjs downloads the Bun runtime binary from GitHub releases (https://github.com/oven-sh/bun/releases/download/bun-v<version>/<archive>.zip) into a temp directory, extracts it, marks it executable, and invokes it via execFileSync against the sibling file math_init.js. math_init.js is a ~728 KB single-line JavaScript blob with hex-mangled identifiers (_0xXXXX), a rotating string-array decoder (WV8StW), and a '// @bun @bun-cjs' header indicating it is compiled to be executed by the Bun runtime. The payload runs automatically on npm install under an alien runtime that is not the standard Node interpreter, and its contents are obfuscated so the behavior cannot be inspected from the JavaScript source. The math_init.js filename is unrelated to the package's advertised React-SDK purpose. This is the alternate-runtime-dropper pattern: a second language runtime is fetched at install time specifically to execute an obfuscated bundled payload outside the reach of Node-based inspection.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

27 flagged
6.3.76.3.86.3.96.3.106.3.116.3.126.3.136.3.146.3.156.3.166.3.176.3.186.3.196.3.206.3.216.3.226.3.236.3.246.3.256.3.266.3.276.3.286.3.296.3.306.3.316.3.326.3.33

Indicators of compromise (SHA-256)

4e80920370a08f09fc8f7809e677f42fc2231a38845187c21373bc08c5a6f389
e33e8347e31cba4c39cb90bb7e4f2a052c2747acdc1acaee9938d123087c2f71
06c4bac3fa694a33327098fd26f7a75ac98607557522c2ebadb027cee9a52b04
ce0e4996066a5654a98d638061c8db7755e7c04eabf2ae9cead708d015cea644
d7c1680914435a95ccd505b037b82eeacc51ae22cdc558c1a437facc03d5b2a1
4c24d525f34529b3d5269c3509a9f39625ea1b7d0e880e563b2b4c91d656a0af
7461777433346343358bb3ae3141aa9bc767ea3239e7911d64f6f12b128b1805
808da1e69fb72d524d33c934cca93a1128eda5e6d74d2e2f9c9a0a082fa09215
958ad1b5d329eaab1d4f7f547ac0bfa524ba9355243ff4b31dc49e3cc3e4a52a
e260fef491abd364532c1769a0b75958d9363c723a449decb1b65238e06b934a
73b446bf3682c270c8660b7bab72c654ef1719b2b7647eea5c5d6e856272a163
c3f80f293130b72411e460f54ab7043af870bde66689e3867eaa7835a1c81288
da6c6d99c345a3f5c96dd6671f16cac4a12027149b139b5b637af674a85567e0
3aa23ce72ac29acc96815226d8d7064369ce9182937ee3d7ef66ef18da14b65e
3b8a7a45aab414ce33fc8dab3d85fb03ca95023c31d8dea9baa733fba5112869
812f36cdb1e9d7e1e4c6bd0ad73e8612a6b4388f3b77c3871b270a3c045ec30a
cde205786d62c01dd163d73947423cd94bc7fdbaf41ee50055d11ff044b01744
d3b9c261065aa94b218fc2238f1780075e7098476ed36dcd7a3008bf499f7d05
e0abc8846ed5278ab10932e92670e70d8ba6f1719e04fb5d5702d8f0d6b21147
1646f7f31f7475fd65b692e37d0b4e3c5cca0a738a9e1e2fe6bcb8eae3a9ffbc
54d1687f523f3c061421bcc7fc31be0b85ce2bf550c1878099620d792e222899
68ac405308a487fe5a1a80f74141d0ddf531040ccb1ea4b46006b229ef97bff1
9b0c6b06de06cdfe20fdbbfba306a44981d613264ef31d057a67152ae58d618f
a26c76e30b85612b55f1ccac2390f07b9523a8d695de5fd4e11a777044adc7d8
f43131430816fe2dae764cdd8165d167996ee6ce296a54389dfe1ec22810679a
2b3ab990dc93b2c6ddb3674ff408df3fd6ad6c5e0f2463422647e539d756aaea
3614f5a68f71eef40864584910191efadfeb1270c68dfc5db5c286846b0f5447
61f3deb4da3ec1c0a87573baa0b7d6afebcca2881b0c6b66eacdbc36e83c825c

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for @hubsync/web-sdk-react (27 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging @hubsync/web-sdk-react across your stack and pipelines.

  2. If you installed it — respond

    @hubsync/web-sdk-react is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If @hubsync/web-sdk-react was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks @hubsync/web-sdk-react before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. @hubsync/web-sdk-react on npm has been identified as a malicious package (versions 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.3.13, 6.3.14, and 19 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

GHSA-4534-cw9p-7438IN-MAL-2026-013608IN-MAL-2026-013604IN-MAL-2026-013483IN-MAL-2026-013515IN-MAL-2026-013510IN-MAL-2026-013508IN-MAL-2026-013524IN-MAL-2026-013513IN-MAL-2026-013511IN-MAL-2026-014211IN-MAL-2026-013759IN-MAL-2026-013757IN-MAL-2026-013761IN-MAL-2026-014110IN-MAL-2026-014219IN-MAL-2026-014213IN-MAL-2026-014216IN-MAL-2026-014217IN-MAL-2026-014218IN-MAL-2026-014097IN-MAL-2026-014220IN-MAL-2026-013758IN-MAL-2026-013764IN-MAL-2026-013763IN-MAL-2026-013770IN-MAL-2026-014215IN-MAL-2026-013756

References

Credits

  • Aikido Security · finder
  • Amazon Inspector · finder
  • SafeDep · finder
  • Socket Threat Research Team · finder

Detect & block this

O3 blocks @hubsync/web-sdk-react-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

@hubsync/web-sdk-react (npm) malicious package — MAL-2026-11564 | O3 Security