Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

@pablo_clueless/printrnpm

Advisory published Updated

@pablo_clueless/printr is a confirmed malicious npm package (MAL-2026-14329) that executes malicious code on install (malicious versions 0.1.2, 0.1.4, 0.1.5…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in @pablo_clueless/printr (npm)

MAL-2026-14329
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall @pablo_clueless/printr

What this malware does

The package was found to contain malicious code or consuming dependency that contains malicious code

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

6 flagged
0.1.20.1.40.1.50.1.60.1.70.1.8

Indicators of compromise (SHA-256)

457ae9252deb98f90edc93ff7effd91dc23b5d77beb6d942396e5ce15c6a7ea4
13ba2a3695f8d0fa63fb6558e66660f1e3b4a6f4eb080b86c486daae6f55102b
314f6b7b256dc1d7439c6f92b679667602c0735137a0459df18e6ee50d6a9a4b
5a7db730115ece6b38a0811480eb544011eed1c1bd6cbde9c088cdb71bcdd271
e4c590ad71452959dac3b31e844574604f63edbe1af6cdab1db266a2f7453cce
f525ff403d069b04e712144f0e4a1f0720d3d3dcb7c3ea815eae9a9b53ee99eb
f750d982e6f1c83d5b4e5235fb6faed0341c96a850cbf35c5cee607832bfac16

Detection & response playbook

Malicious package
  1. Find it

    Search your lockfiles and build artifacts for @pablo_clueless/printr (6 malicious versions).

  2. If you installed it — respond

    Remove @pablo_clueless/printr from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If @pablo_clueless/printr was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.

Frequently asked questions

No. @pablo_clueless/printr on npm has been identified as a malicious package (versions 0.1.2, 0.1.4, 0.1.5, 0.1.6, 0.1.7, 0.1.8 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

GHSA-3jxq-xch2-6hpmIN-MAL-2026-018475IN-MAL-2026-018486IN-MAL-2026-018484IN-MAL-2026-018478IN-MAL-2026-018472IN-MAL-2026-018474

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks @pablo_clueless/printr-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

@pablo_clueless/printr (npm) malicious package — MAL-2026-14329 | O3 Security