Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

@ikbal_fadilah_vanexa01/vanexa-agentnpm

@ikbal_fadilah_vanexa01/vanexa-agent is a confirmed malicious npm package (MAL-2026-13364) that steals credentials and exfiltrates sensitive data (malicious versions 1.1.51, 1.1.52, 1.1.53…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in @ikbal_fadilah_vanexa01/vanexa-agent (npm)

MAL-2026-13364
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall @ikbal_fadilah_vanexa01/vanexa-agent

What this malware does

Package ships an agent daemon (vanexa-agent start, entry bin/vanexa-agent.js) that receives commands from a remote phone app and executes them on the installer's host via child_process/spawn, including powershell.exe and inline JS/Python evaluation. Rather than the LAN-only WebSocket architecture described in the README (which claims BYOK with no middleman), the compiled bundle hardcodes two Cloudflare Workers endpoints — vanexa-agent-relay.hanazaki542.workers.dev and vanexa-ai-proxy.hanazaki542.workers.dev — hosted on a personal Cloudflare account (hanazaki542) that does not match the npm publisher (ikbalsakata500445jensen). Commands from the phone client and, via the AI proxy path, user-supplied prompt content and API tokens transit this third-party intermediary before reaching the local execution sinks on the installer's machine. The primary runtime is shipped as V8 bytecode (dist/bundle.jsc) produced from dist/bundle.cjs at postinstall via bytenode.compileFile, and the bin entry loads that bytecode with require(bytecodePath), reducing auditability of the network-driven exec path. The combination — network-sourced commands flowing into local shell/child_process, a hardcoded author-controlled relay whose ownership does not match the publisher, and a bytecode-compiled payload — makes normal operator use of this agent equivalent to granting the relay operator remote command execution on the installer's host.

Malicious versions

35 flagged
1.1.511.1.521.1.531.1.541.1.551.1.561.1.571.1.581.1.591.2.01.3.31.3.41.3.61.3.71.3.81.3.91.3.101.3.121.3.141.3.151.3.171.3.191.3.211.3.231.3.271.3.281.3.291.3.311.3.321.3.341.3.351.3.371.3.401.3.441.3.45

Indicators of compromise (SHA-256)

481daae8905848ad63e1ea0680645761de3594c5eaa017e9e6f6ea8fe6e2282e
d9f41ee3ef2d3e711f00b2d2f5df471d2c2c1f4e7be9b4563017526c23bd14b3
1694969f49b4c30e299fc9b51dd60e8e24faa97c853c663b5fad018cf6ed7163
57c73c2e900eee675453cbc41cad5992640f1f9051bd49ea789b16a13328e8d4
60838012b6a1c5baf88d9034d495dcfad4b4b4bed2eca7740214896931823e6d
f01d8891e773a84f7171ba737ee556bc7116dccd30c73f090dc24f24143ad82f
ffd15f555cf1d4e138b64b2ede6dbdacacde6cbd4412f3791a3a54f25b81d655
0fe7fb20ec36246992d1b4faaa2b1e5afae4e37cda843fc6ae7848dfc2b3f8f2
78ba42c806346cb3d718d37a576e5237be553c0c00dfe9c27f224fb96962b4f9
92597f62bf4b6df199a7784aa71dfbf9b9e40b59f9580bec8e782e6312940428
9a7cf61c610e5a38f9efbba3a984886acd7d6e933e95bbbeffc526b9592f3ee3
aaf0c2e39ba69473adfb41e866f8faeb413c8ca83136bae9a78710192d7aa8fd
ad5455301be007ba880e5dc2a4e7912fa761ca2d2fd83f027d6560a3b6a93e7c
aead634b0fe8b0dd2adf56d74a20306c7a53def0da70ba15fdce13785fea8af6
b8174bacba0ef373f43333e2ede4dfe730ed4d8675f32766f1a97de25f9e3566
daeb89ff38231ef6701b4402aab97c44d5709148a8be71f0751458e0393f7964
356fd03c2bd7c9bafd3a3d1f4e21f2b982f364c1f9035440802108ab6fcac764
5879d9167255b615df85872c600553d5b2c83b99420ff34806c393bceaa86661
cd6e2b04b9a1b32cde1e1f7f9b06ed1b553c02a4791489f849acac8080285a23
ceef7861c370625085d1a0725922c8a184265a335c31095529a8dd58f04c58f7
049497a6b0aafd1f65a52984e227c333c0809946fa5cd4c899062e442fd5fdfb
10b28cb6809fceca186b78441fa1469c355bc4d2cba5ec5a826bf91df5b1a6b8
cdb7a39c047dcbc3b1bea5beb43d9b6bcabc631e604ba0cbf903e95ed17c4016
ef6d2ea845e3d127d15ee799d878dee6655365eacb5dc306f564d59a891ebdf9
367330aab67ac352c10ddb6e142dade22d8111ce38bd1522270a54f34dcd05f2
5037e0458321aa0485797aca70eecf5781d98d547e0b7ab736e0a13169a20509
7f717cd4c6b774f55fe369a298f16814c3cdf0c0e34733c54fa373319a81080f
8539ccd87d3b47388e734dcca16f8cb2569eccddc83d3f6a7eda3c08b3dc9a8b
f1e2e6e78b5768af12f029dd2151f4a833905cb9aefa8f31675b4b18e0bc2764
0e4f917d64f544bfb61447ee39df17c6ec4723f1fa681d57605b9a9d2d88e752
52b1477c5187703dab87d6be6933d62de4c4244ab3340586f85b530e05470aa1
f2bc78f91b7358c8a49eee890fe0e399f65c131dd45c4fb1c988ceee3ec0c68b
fa606654f20a78ae48039cf7fda911e20fb3f367a94d1c046c210f78e62515bc
fa862fc18478ee5be3da3ed42fc0e43f1d770e602732ddb7ad78657f5cf8bc43
c7dd771763426495461120c20782ffd986494783c3120a25c5d810d256542f35

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for @ikbal_fadilah_vanexa01/vanexa-agent (35 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging @ikbal_fadilah_vanexa01/vanexa-agent across your stack and pipelines.

  2. If you installed it — respond

    @ikbal_fadilah_vanexa01/vanexa-agent is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If @ikbal_fadilah_vanexa01/vanexa-agent was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks @ikbal_fadilah_vanexa01/vanexa-agent before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. @ikbal_fadilah_vanexa01/vanexa-agent on npm has been identified as a malicious package (versions 1.1.51, 1.1.52, 1.1.53, 1.1.54, 1.1.55, 1.1.56, 1.1.57, 1.1.58, and 27 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-015847IN-MAL-2026-016556IN-MAL-2026-016582IN-MAL-2026-016587IN-MAL-2026-016557IN-MAL-2026-016579IN-MAL-2026-016574IN-MAL-2026-016558IN-MAL-2026-016571IN-MAL-2026-016565IN-MAL-2026-016586IN-MAL-2026-016576IN-MAL-2026-016575IN-MAL-2026-016560IN-MAL-2026-016572IN-MAL-2026-016589IN-MAL-2026-016588IN-MAL-2026-016566IN-MAL-2026-016563IN-MAL-2026-016559IN-MAL-2026-016564IN-MAL-2026-016570IN-MAL-2026-016573IN-MAL-2026-016562IN-MAL-2026-016585IN-MAL-2026-016568IN-MAL-2026-016567IN-MAL-2026-016580IN-MAL-2026-016577IN-MAL-2026-016561IN-MAL-2026-016578IN-MAL-2026-016584IN-MAL-2026-016569IN-MAL-2026-016581IN-MAL-2026-016583

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks @ikbal_fadilah_vanexa01/vanexa-agent-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

@ikbal_fadilah_vanexa01/vanexa-agent (npm) malicious package — MAL-2026-13364 | O3 Security