Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

@ibrahim1337/baksennpm

Malicious code in @ibrahim1337/baksen (npm) Remove it immediately and rotate any exposed credentials.

MAL-2026-6575
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall @ibrahim1337/baksen

What this malware does

Package @ibrahim1337/baksen ships a Windows x64 infostealer toolkit that targets Chromium-family browsers (Chrome, Brave, Edge, Opera, Opera GX) on the machine running the CLI. The JS layer enumerates browser profile directories and reads the 'Local State', 'Cookies', and 'Login Data' SQLite databases, executing queries such as SELECT origin_url, username_value, password_value FROM logins and SELECT host_key, name, encrypted_value,... FROM cookies. It extracts the AES master key and the Chrome v20 os_crypt.app_bound_encrypted_key from Local State, then decrypts cookies and saved passwords with AES-256-GCM and writes the plaintext credentials to local _cookies/ and _passwords/ directories. A bundled opaque Windows native addon build/Release/debugelevator.node (declared in package.json files, os: win32, cpu: x64) performs the App-Bound key elevation — the documented technique used by recent Chromium infostealers to bypass Chrome v20 encryption. Strings inside the bundle include 'DebugElevator - scanning all detected browsers', 'Launching... browser(s) in parallel for App-Bound key', and 'APP-KEY'. A license module fetches an allowlist of valid keys from https://raw.githubusercontent.com/tabo1337/SaatPCBKod/refs/heads/main/key.txt (an account unrelated to the publisher) and caches the result at ~/.baksen_cache, indicating a sold/distributed hacktool model. Package metadata is placeholder ('hadiyapic' description, github.com/yourusername/baksen repository URL) with no legitimate provenance. Installing and running this package on a Windows host with any of the listed browsers results in extraction of saved passwords and session cookies — credential theft against the machine running it.

Malicious versions

19 flagged
1.0.01.1.01.2.01.3.01.4.01.5.02.0.02.0.12.0.22.0.32.0.42.0.52.0.62.0.72.0.82.0.92.1.12.1.23.0.0

Indicators of compromise (SHA-256)

2f30b699682dfdb02ea4c678ae852f449ee33f3aff57b44206a52387fdacf996
3594b83aa12e5ab4985211494b6b6f73f6def91aae1210e0ae55f28e572d79a8
3c70e5ca03f88c3002eb0d2dcb4bd54dd235b13e91565d112deb4fa370181010
491ac4df82e71d23eb5184150e9890b8aaaf00183be840b75e14ec1c6ff986a3
211f1e2d92ecf1d43d70ef0befd0487cf53560903f2bfbee7b19d25c8f8c0e4f
7550920fecd292561e960d629cd5804c2cebdf1539b9accb37ff5e7b3d2ad521
817a6ab6813ba9075b45acbc1f0ef7f33a07364de3823e0d6a01e9be05befb9d
9e9de53d5f33d8a032f291b8100a65a27143acf1b365b82ecc6c16f8770e11ed
a4d684b9f5693d578fd1d75a342a05465ea17aab40566635a2ed00864da6033b
aac2f729d44abcd0e848af5ca12b39cf2d5f23d03d2358108bbf247550e5bd6b
ea195bd44e54cd1051fc279a0e871b02c15eea04f65c80979d756fa767f541b4
1947631168e3445908dd4d38da1634017df4f2e45367c921904058d0d1790548
4e09d0dfdafb826719eb449fcb2bc5b1614a8d5f1d11aa8912e1b3bd4a7a27bd
ee205cd81618df0426ecb43fd3724c25504ff94173673b63345ea2d59c539734
0af670d483174d4af491ae8b09c9f0f189117713d59db1091e9f274000b06138
44e6f2c3fbd8aa3a6ad232333d087b2e2eee5d6ed59ef8ff8af0693226c8cdbd
fba494a8bdd13a7dd4ea76b1792963c4d020888ed0469b1db90fe8a907983dd2
4af5d22240bab8490ad45718eef38e3d47f6d3a63c62307db6690621fa583eac
9b8a290621c1f7e6d8d8025329998a4a6830cff8d9213c683158d55b37dfaafe

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for @ibrahim1337/baksen (19 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging @ibrahim1337/baksen across your stack and pipelines.

  2. If you installed it — respond

    @ibrahim1337/baksen is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If @ibrahim1337/baksen was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks @ibrahim1337/baksen before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. @ibrahim1337/baksen on npm has been identified as a malicious package (versions 1.0.0, 1.1.0, 1.2.0, 1.3.0, 1.4.0, 1.5.0, 2.0.0, 2.0.1, and 11 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-007737IN-MAL-2026-007740IN-MAL-2026-007739IN-MAL-2026-007738IN-MAL-2026-007974IN-MAL-2026-007969IN-MAL-2026-007970IN-MAL-2026-007973IN-MAL-2026-007975IN-MAL-2026-007972IN-MAL-2026-007968IN-MAL-2026-007971IN-MAL-2026-008939IN-MAL-2026-008986IN-MAL-2026-008950IN-MAL-2026-008974IN-MAL-2026-009473IN-MAL-2026-009429IN-MAL-2026-009434

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks @ibrahim1337/baksen-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.