Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Part of a larger attack: @ornikar published 42 malicious packages. See the full campaign →
Malicious package

@ornikar/apollo-link-timeoutnpm

@ornikar/apollo-link-timeout is a confirmed malicious npm package (MAL-2026-11739) that steals credentials and exfiltrates sensitive data (malicious versions 1.4.2, 1.4.3, 1.4.4…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in @ornikar/apollo-link-timeout (npm)

MAL-2026-11739
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall @ornikar/apollo-link-timeout

What this malware does

npm/@ornikar/apollo-link-timeout is affected by the large-scale, self-propagating npm supply-chain worm of 2026-08-04 (the "Shai-Hulud: Here We Go Again" wave) — the same campaign that began with the compromise of the keyv and cacheable maintainer account. The listed version(s) were trojanized and republished by the worm after it reached an npm publish token belonging to a maintainer in this namespace; the payload enumerates every package a stolen token controls and republishes each with the same hook, so many packages under this scope were poisoned in the same short window. Every poisoned release adds a preinstall hook ("preinstall": "node setup.mjs") that runs on a bare npm install, before any project code. setup.mjs downloads a standalone Bun runtime and runs a byte-identical, heavily obfuscated ~728 KB second-stage credential stealer (shipped as Math_Symbol.js / math_init.js). It harvests GitHub, npm, AWS, GCP, Azure, HashiCorp Vault and Kubernetes credentials plus generic secrets and private keys (TruffleHog-style sweep), reads CI/CD secrets and identifies build runners, then republishes further packages the stolen token can reach. Rather than a fixed command-and-control host, it exfiltrates stolen findings to attacker-created GitHub repositories (descriptions reading "Shai-Hulud: Here We Go Again") and over DNS. Treat any environment that installed an affected version (with install scripts enabled) as compromised: rotate and revoke all reachable credentials (npm and GitHub tokens, cloud keys, Vault/Kubernetes secrets, and CI org/repo secrets). Part of the August 2026 npm worm that poisoned 400+ packages across many organizations.

package.json declares preinstall: node setup.mjs. setup.mjs is obfuscated (hex-mangled identifiers, per-function string-map indirection hiding URLs, filenames, and shell commands) and at npm install time downloads a Bun runtime zip from github.com/oven-sh/bun releases into an OS tmpdir, extracts the bun binary, chmods it 0o755, and invokes it via execFileSync to run the co-shipped math_init.js on the installer's machine. math_init.js is ~720KB, uses string-array rotation obfuscation (WV8StW push/shift routine over a large constant table), is not declared in package.json files (which lists only lib), and is unrelated to the small advertised apollo-link timeout logic in lib/timeoutLink.js. The tarball is published under the @ornikar scope but declares author Dustin Callaway [email protected] and repository github.com/drcallaway/apollo-link-timeout — the original unscoped upstream — indicating a trojanized republish of a legitimate small library with an added preinstall dropper. The alternate-runtime delivery (fetch Bun, then use Bun to execute a bundled obfuscated blob) is a known evasion pattern that hides the executed code from Node-based scanners.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

10 flagged
1.4.21.4.31.4.41.4.51.4.61.4.71.4.81.4.91.4.101.4.11

Indicators of compromise (SHA-256)

a315027f00f25b75b2529b3ac88da5fb76cbbcc4a4c9182d4a8f523e26c6122f
8071268439c7f433c9b316636bdd2efc3e97b6dfb8b1d21b429c8840335a751e
502e8693e4a71772a88c03da033a414086e196d9e5be8b3b79ec68da977c77da
5a6550e47c1eb3da70edf2ef39093825aa314396375d4ad3cc70f2d260138be6
de49fd68f88a86f854c9b8f520a1fa9a3fb5647235fad3ee29ac3a1d7b1b8fc7
e7e19a0c40f2f14b9b213c352335b6078bec8a9e7aa8aa8b1169c4ccd2b7d6b8
ef531c08f4e7306cf91bfb47baceff0f1551d7ca9a6596fb4a7652d9c6cefc9f
0fb00d9b18bebdd02ed8476ae564c443a662932c7e536b480bd8a69b6b65d55e
3ab13652554f40e20143d6434963b7de218bf9383a9b8d2e1d9bea93924f9e74
4d74f29dd5905e5f4b16450e86359d952a7fa9256c9a508e143c9f29d5ba3f8d

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for @ornikar/apollo-link-timeout (10 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging @ornikar/apollo-link-timeout across your stack and pipelines.

  2. If you installed it — respond

    @ornikar/apollo-link-timeout is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If @ornikar/apollo-link-timeout was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks @ornikar/apollo-link-timeout before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. @ornikar/apollo-link-timeout on npm has been identified as a malicious package (versions 1.4.2, 1.4.3, 1.4.4, 1.4.5, 1.4.6, 1.4.7, 1.4.8, 1.4.9, and 2 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

GHSA-9xf2-6w63-p3qhIN-MAL-2026-011394IN-MAL-2026-011629IN-MAL-2026-011705IN-MAL-2026-011717IN-MAL-2026-011716IN-MAL-2026-011627IN-MAL-2026-011905IN-MAL-2026-011628IN-MAL-2026-011906

References

Credits

  • Aikido Security · finder
  • Amazon Inspector · finder
  • SafeDep · finder
  • Socket Threat Research Team · finder

Detect & block this

O3 blocks @ornikar/apollo-link-timeout-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

@ornikar/apollo-link-timeout (npm) malicious package — MAL-2026-11739 | O3 Security