Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

@lyxa.ai/corenpm

@lyxa.ai/core is a confirmed malicious npm package (MAL-2026-13434) that steals credentials and exfiltrates sensitive data (malicious versions 1.0.8-debug-1, 1.0.13, 1.0.16…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in @lyxa.ai/core (npm)

MAL-2026-13434
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall @lyxa.ai/core

What this malware does

The exported bootstrapCore() unconditionally initializes the event bus with a hardcoded amqps:// URL containing embedded credentials for the author's CloudAMQP broker at dog.lmq.cloudamqp.com/vgyuplrd, with no override parameter. All events an installer publishes via publishEvent() flow through this author-owned exchange, and subscribeToEvent registers channel.consume handlers that JSON-parse incoming AMQP messages and invoke installer-registered subscriber methods as instancemethodName — meaning any party in possession of the shipped broker credentials can push messages that trigger arbitrary decorator-registered handlers in the installer's process with attacker-chosen payloads. ConfigurationService defaults redisURL to a hardcoded Redis Cloud endpoint (redis-12296.fcrce173.eu-west-1-1.ec2.redns.redis-cloud.com:12296) with embedded credentials, and SecretManagerService instantiates a GCP SecretManagerServiceClient using a shipped service-account private key for project for-poc-325210 to fetch MONGO_URL, which mongoose.connect() then uses — so installer cache state, secret lookups, and DB reads/writes default to author-controlled cloud accounts the installer never configured. The compiled bundle additionally ships a live GCP service-account private key ([email protected]), three Firebase Admin private keys (projects for-poc-325210, lyxa-rider-88939, lyxa-shop), a Redis Cloud password, and the CloudAMQP credentials, giving any third party administrative access to the same author-owned backends that installers of this package transitively depend on.

Malicious versions

20 flagged
1.0.8-debug-11.0.131.0.161.0.231.0.371.0.561.0.791.0.1291.0.144-test1.0.145-debug1.0.162-test1.0.2011.0.2061.0.2811.0.3331.0.3861.1.361.1.471.2.241.2.43

Indicators of compromise (SHA-256)

0aab606a35cc885f17daa4b943ffbc1ee3e691adfffa24513e5741758090953e
28e9b605fd0af18680342f725e028fc612744a47e2ddf6dc86b4352babc60bde
9bc2087e4e8aefbb672176906a2c4024a3deb2b6b4114dcd2d75c5d222558588
e8f074d2f617feee28f5f09f393dd6810df53a03b48cd23111239972d4dc6f7c
f9322cb3d37df8cb254835171dd2d48cee1076ae99e09344db7faa6c8ae15212
c120262f3806a610de489ebcba7302780d2de23d17a488f5f234e4a7f3e13d65
d4092c78614b93ae58f52ffada20d6d58314406edb72d0629e991148a6d0c8e4
e4814f0506585fa3e90397e31051bcf2f7eb91f431f546f199b3ffe9afb51bc5
9cafacec65b89c0bcfb7e67a3ddc0343a810ebebefec2b351341920e403545e9
a25f0470927b0a29c20475fea96ba8ae11cc06b574aefea78b7359f2aca853ad
d28aa236c1d0ad9141c90c5da56e1e7d859f64f6ad51b03fbe20de29606fba46
311248c420ae79e6397bb7961b4f2ab734a76815214cfe411b81ec28f95e9b3b
481ff2b9d0a967572af464a2cfe585ab185912cff1f7c8eb1fa22195171199a1
5cf1130fa5c4ab011358f55541cb7e6ef97d3c399f680d04313d143f6260daf4
94e7260ac245ed2753d2bb1457953b3dc3051bea86e74ef0e8e8679866b5a99b
d2ae7e523e4ec08064360c7641b197eb9a0edc4906da8d4a61c29e0772e52bb1
8810fa7234da9bf5bfd19d413f0c4b4e4fb82f178764d46b5db7c02a5caddf9c
cedab42884ee8af136243a5af2230c36e900eb0207fb2b47c6e4f25c10d4596d
1a32d4762c92b12ad7fd0567dfa0f07470a01884303acdc7a3585bfb4ad7fff2
204fa170dfe32f0b2ef2e9be591f64578fedc097fd163b66fdf28758c6598990

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for @lyxa.ai/core (20 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging @lyxa.ai/core across your stack and pipelines.

  2. If you installed it — respond

    @lyxa.ai/core is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If @lyxa.ai/core was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks @lyxa.ai/core before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. @lyxa.ai/core on npm has been identified as a malicious package (versions 1.0.8-debug-1, 1.0.13, 1.0.16, 1.0.23, 1.0.37, 1.0.56, 1.0.79, 1.0.129, and 12 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-016721IN-MAL-2026-016725IN-MAL-2026-016727IN-MAL-2026-016735IN-MAL-2026-016737IN-MAL-2026-016736IN-MAL-2026-016728IN-MAL-2026-016723IN-MAL-2026-016731IN-MAL-2026-016720IN-MAL-2026-016733IN-MAL-2026-016726IN-MAL-2026-016739IN-MAL-2026-016732IN-MAL-2026-016724IN-MAL-2026-016734IN-MAL-2026-016722IN-MAL-2026-016738IN-MAL-2026-016730IN-MAL-2026-016729

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks @lyxa.ai/core-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

@lyxa.ai/core (npm) malicious package — MAL-2026-13434 | O3 Security