Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

@onescience/onecodenpm

@onescience/onecode is a confirmed malicious npm package (MAL-2026-10717) that executes malicious code on install (malicious versions 1.14.50-202607161038, 1.14.50-202607161139, 1.14.50-202607161642…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in @onescience/onecode (npm)

MAL-2026-10717
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall @onescience/onecode

What this malware does

The npm postinstall hook runs ensurePlatformBinary(), which downloads a.tgz archive from the hardcoded bare-IP URL https://218.90.133.98:4443/onecode_tgz/onecode-<ver>/onecode-linux-x64-<ver>.tgz, extracts it via tar -xzf, chmods the extracted file to 0o755, hardlinks it into bin/.onecode, and the shipped CLI launcher invokes it. The HTTPS request explicitly sets rejectUnauthorized: false, disabling TLS certificate verification, and no hash or signature check is performed on the downloaded artifact. The download destination is a bare IPv4 address on a non-standard port, not a publisher-owned domain or a recognized release host. The package name and launcher (@onescience/onecode) mirror the unrelated 'opencode' project — env-var fallbacks reference OPENCODE_BIN_PATH and bundled asset directories are named.opencode/session-seed and.opencode/oneskills — while the executable payload is retrieved from an unrelated hardcoded IP endpoint. Anyone controlling that host, or any on-path network attacker (TLS is disabled), can deliver arbitrary code that executes on every installer's machine.

Malicious versions

54 flagged
1.14.50-2026071610381.14.50-2026071611391.14.50-2026071616421.14.50-2026071617101.14.50-2026071718331.14.50-2026071718411.14.50-2026072009111.14.50-2026072017411.14.50-2026072209561.14.50-2026072216491.14.50-2026072309081.14.50-2026072311111.14.50-2026072313441.14.50-2026072313541.14.50-2026072315151.14.50-2026072409161.14.50-2026072709201.14.50-2026072714561.14.50-2026072715451.14.50-2026072718081.14.50-2026072815271.14.50-2026072816131.14.50-2026072817371.14.50-2026072817581.14.50-2026072818141.14.50-2026072818381.14.50-2026072819281.14.50-2026072910131.14.50-2026072911161.14.50-2026072914171.14.50-2026072917051.14.50-2026073016001.14.50-2026073017581.14.50-2026073109071.14.50-2026073114491.14.50-2026073117321.14.50-2026073117561.14.50-2026080108271.14.50-2026080315141.14.50-2026080318121.14.50-2026080410431.14.50-2026080414161.14.50-2026080416141.14.50-2026080416531.14.50-2026080417241.14.50-2026080418021.14.50-2026080418281.14.50-2026080514181.14.50-2026080518261.14.50-2026080614591.14.50-2026080617531.14.50-2026080709221.14.50-2026080711431.14.50-202608071618

Indicators of compromise (SHA-256)

5928c2edb03c7fc9a909b2ff56355dde83cab5e7776512204a35e274120932f5
d334dd52244b44793af06be86dfd8d0de20ea8bb6d28cc1e4016b5fa45432578
fa28860ddf0274e1a39af78373aa118824c4479ef158d166d230de533a1b34d0
20c0ef93b477ae7e528e4a59da63f1cc178fc9395a6d3879c49da64b1c2fbc88
42ed0e0defde1688d2260c590a20648fce6f8708e4648720a50094003be1f837
5edf043d9db62c55c8c163b9ec0e52bcb542d52191d1b1ba643ddcbc17ea5df7
020acb54b3ef710c8d3e0085fe571c82105d078129d1a9a050c07a79c2d12d2b
0e7ae1c3e4aed6fbc817d72c75ccc2a24c8005ccbf0e4e74fb47de144514b4a7
3b22bb450edcdaba7c3c40098eddae048f245de14c9605783b18652dd917a332
3eda8f4a2aea77f15f7347b8a2e5a0bfdcbd8d7ac5f3a8184a722636ae035bae
4bba69b51e2e39542b27438d3a34a29165dd37f02787484dac7068c17be1e6a3
6713a2476cbcfbd9cc2d5f4b299f86e050efa24a0774c4363c36625e6af34c9e
b276b0abc82fba54bbf841318aef59fe1ea855d1a6c2a67f90ee78025f55a026
b6c67dfc5ec3dfedc2e04693bb6486f86ab32600c880fcc74103c80fa0578e4a
3782b1d42fbc885c5d6f4549274bb5a8e8d1a1d7b33931b7cbd8d0bcfd502412
3f2c83e27a4d5d8a897030b13d5bf4d2c26b38069e53a2d4d6eeb653dab7db92
5aa68b21d0f3a19c1f5fe2639cc4c9ec77d1a96dc28928a7430ec566e6ab515a
6a058f44e50e02375a01e704b632ec71f65a8f3393c1c5cdbb578dad29a2b0d4
7138306ad2ed4c2181a4c24587c0c78585c31878edf3dba159c592bea4de9da7
8987ef65f2b72c34365038323ea0c61d7a6910c1d7e2ecf819ba7b0b8df7b968
e2453ca4f361157f5b95ebbc8e1ea7c8f82d19e54462f5d586dcc75d1b48d5ae
13c3495688857a8750947b85ab9472344dcfb345e48d9f8483baf1f80be38d3e
18422bf33af9d1707cd4a95daa05c872bbe3d8fbd2c1b5736af9f4735638069e
406adb8670d5d195ca6298fcad1c5c9184867cb57b1703310977ac7b5231bc9b
45f7fa9c02faf00ae29b29da19e7f240d5b21e2fa7dfced97e8a70c605181f40
4d0a88be7a7751280c18029164ccc2c99a9e6df4c4311f8271fc2d4178b6409b
6901b470b2dd948fcd7dd5adc48e74f849ac2c1277df90ad7ecfc829659efb03
07d42b1f329d1fd0ef3a9c57d0a523103d4b971e02b4ca09dbf87781376a38d5
27a4a1b7cd0d13d799c102e83ec8be78455bc444c063d2573c814b076b30f090
5ca3f1516a7b5612db43a5de5c058a553fef967a94c25119939679ba0d727772
f81b171c3e580edcfac82fe2cdc5db611735f4c47ccef8a131e2941ae2d5d8ce
fea78f743ba6e4f88317b38be3b51a2c9f4c9a092bd4355dca76a960c5c81c63
0e4999b5f60515ed2433bd2ace50d69d2c17246b859e615e6736c947f1ecc122
37bf72a75a7b01d9770282d4addd8adf5fa1ad2f180984f1494c46f1df61214f
52d195c78fae104cb20948b948c3fce1429a8c7181290eb608e14b8cb501e63a
644160ed0c64e0f0d2c7521a081a6f85904cacf0df5883aa1fc64505d6b100f2
713bf7fce40e177608dd5145e1662b4efd3da6c1597d9a1aeb15d7715b865205
b9030ee9b873d47b25e221c2a12659ac8d7f28fd6f620fd118981d4c3b5b4158
f928ad8157770e106ddae70411f88b51b5b7df3b2f8c29c6f0a5df35ad8925f3
32f21903ba7f36c95db3b5d232c7a611add99ef606aa0f254778b6f07602fed4
33117e2d408ed451c4a4322585a33518a7e60d2f161149ac6bb34f957af36b4d
353bf9f994768a380ea1e3d1df3abe1cd9c5bb95b6edd46ee046673f0837c9de
37bcc48cacbe1078c0a156a03aa38801038fa24a1ab45a2cd1deaa5a75b119b8
48dab1d91e605222b7b48cc4c368944832584c12e86c7f0e37d8aa9386a074f6
4b1c06b0b5671ba7ea9062ac239f5f0e3d569df7fbf2f45fa25b2d4b27c9d208
b3761ce1f0e4ecf6893d900c9d91e50650f79f56a79398549892b21c112b04c5
bed46c93dbc131361e9bee5c3670dd0a795ffe64fb2ec821c14d1432eede3b45
155921e76e3d1f3bfe82f3afa2805e7afb79dc6b76371d315411ba216665e224
256653c31ab504ff60976c2c7429877bff1e85818d26dd7a55b21c65bef03a47
74ec1bab45a6b596094479cdb58a46f0d557876a0fbf916644c4eef4d11eca2f
fcef18ee955f353cc3bdaeae6276cb5547ff145772d5e75ba38ba23538257b44
76f4efc2e5d92f5066291ba5e97f5f3dee1e273105996405dcc3f98dda95d13e
2cbf23de79fca78ffe5a4f81840208deda5b6e14d3cef5c6a694ffd66b17dfa4
d14bea8230d267d016863789ffdda363c0aaf9711e5224c6b4741d1c53e46ad3

Detection & response playbook

Malicious package
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for @onescience/onecode (54 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging @onescience/onecode across your stack and pipelines.

  2. If you installed it — respond

    Remove @onescience/onecode from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If @onescience/onecode was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks @onescience/onecode before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. @onescience/onecode on npm has been identified as a malicious package (versions 1.14.50-202607161038, 1.14.50-202607161139, 1.14.50-202607161642, 1.14.50-202607161710, 1.14.50-202607171833, 1.14.50-202607171841, 1.14.50-202607200911, 1.14.50-202607201741, and 46 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-010746IN-MAL-2026-010765IN-MAL-2026-010769IN-MAL-2026-016317IN-MAL-2026-016286IN-MAL-2026-016325IN-MAL-2026-016284IN-MAL-2026-016311IN-MAL-2026-016312IN-MAL-2026-016305IN-MAL-2026-016287IN-MAL-2026-016308IN-MAL-2026-016306IN-MAL-2026-016298IN-MAL-2026-016295IN-MAL-2026-016321IN-MAL-2026-016315IN-MAL-2026-016319IN-MAL-2026-016289IN-MAL-2026-016309IN-MAL-2026-016294IN-MAL-2026-016303IN-MAL-2026-016291IN-MAL-2026-016323IN-MAL-2026-016297IN-MAL-2026-016296IN-MAL-2026-016288IN-MAL-2026-016285IN-MAL-2026-016300IN-MAL-2026-016313IN-MAL-2026-016318IN-MAL-2026-016320IN-MAL-2026-016327IN-MAL-2026-016280IN-MAL-2026-016293IN-MAL-2026-016307IN-MAL-2026-016278IN-MAL-2026-016314IN-MAL-2026-016322IN-MAL-2026-016310IN-MAL-2026-016290IN-MAL-2026-016292IN-MAL-2026-016299IN-MAL-2026-016301IN-MAL-2026-016316IN-MAL-2026-016304IN-MAL-2026-016281IN-MAL-2026-016283IN-MAL-2026-016279IN-MAL-2026-016282IN-MAL-2026-016302IN-MAL-2026-017065IN-MAL-2026-017076IN-MAL-2026-017075

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks @onescience/onecode-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

@onescience/onecode (npm) malicious package — MAL-2026-10717 | O3 Security