Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

@postman-cse/okta-aio-linux-arm64npm

Advisory published Updated

@postman-cse/okta-aio-linux-arm64 is a confirmed malicious npm package (MAL-2026-14357) that executes malicious code on install (malicious versions 0.8.10, 0.8.11, 0.9.0…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in @postman-cse/okta-aio-linux-arm64 (npm)

MAL-2026-14357
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall @postman-cse/okta-aio-linux-arm64

What this malware does

The package was found to contain malicious code or consuming dependency that contains malicious code

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

21 flagged
0.8.100.8.110.9.00.9.10.10.00.10.10.10.20.10.30.10.40.10.50.10.60.10.70.10.80.10.90.11.00.11.10.11.20.11.30.11.40.11.50.11.6

Indicators of compromise (SHA-256)

8ecbdcebcf83f23f4d19558c398bbc844436d2f2a186be996e8f4a43a70fc860
05a2f9288ce6a37525823a4f4d41e8a4aaeaea4b0c6e18e6a356bd9d6f49162e
1c1d97982dd4e80b1714528338a3955040fe5dca669f8145afd8933f6e7b2b5f
3bee95cc3790c919fe5d88a682f16433caed6d998811e9d5d2dbc8640fe384ce
423f34673c6e5adf902237be415272aef5c7cca673d4ec7c0f3035a1586f01bb
5b8d3c6af1e852ef1e8c115201d8f7635c5a8514567220d508f46db8bd884ae9
61377cde7c34115b1fb8b6aeb154950ff39b4394739fe7170ae8c729ed22e647
66b4b35fc73a9a8db6addbd95a6df5709eab2eba8706115fb2f1a14c158a3c4e
6a4587f44927c22a50f55203027f7e143f2d562149fc30fd91bcaa9bb739353e
1ee90f01d587c73600cf73fd9031ee0ea80999bdbf11fabec0ae6240f5a26db4
6962d715d0cd7190f5becbb5aa04d23a9dbce05f51e8e56c2f850a5cd90b445c
86b8f14f65e7d8caea7f0090dbc526fba65b1828c442e340424e416bb21ab884
969de0ace4d1a01099ebf4263cd334985b3c82c5028cce7491cf4de30a162434
d78e9ab974a959c368e8ff616db1c21d4439d41fdc8373975b2b76e24a106e0a
307c35fa109579d23221ff054164e41e0ea2a748828c3e8b1aa8cb1d1eb7ed18
3d6eb8b188e295df37ad152f04273e360762f294a2bdb726ca714deb7e3cc00c
45c370f865fa64665b5ff62379d2d35134c1b4462ca01676a4ee250547dbdb1d
5a34f235b1c22cb0faaaa875e8701207d9e108c55cb1dc797b8827300ce43e16
dbeec7f29382d2d07a9289e8e16e6f6dc07083ecf85bd58193e4ee125b16e236
3f8074f877967b892e25786f8d7820f9817b229f0e956306dee32f1536e23c18
7cba0798e1d2cb646d2e283ef2af7178111fa993a81aad02cb5ead5189656387

Detection & response playbook

Malicious package
  1. Find it

    Search your lockfiles and build artifacts for @postman-cse/okta-aio-linux-arm64 (21 malicious versions).

  2. If you installed it — respond

    Remove @postman-cse/okta-aio-linux-arm64 from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If @postman-cse/okta-aio-linux-arm64 was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.

Frequently asked questions

No. @postman-cse/okta-aio-linux-arm64 on npm has been identified as a malicious package (versions 0.8.10, 0.8.11, 0.9.0, 0.9.1, 0.10.0, 0.10.1, 0.10.2, 0.10.3, and 13 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

GHSA-h84r-259m-g3fgIN-MAL-2026-018524IN-MAL-2026-018528IN-MAL-2026-018519IN-MAL-2026-018537IN-MAL-2026-018534IN-MAL-2026-018525IN-MAL-2026-018522IN-MAL-2026-018531IN-MAL-2026-018529IN-MAL-2026-018520IN-MAL-2026-018526IN-MAL-2026-018532IN-MAL-2026-018539IN-MAL-2026-018523IN-MAL-2026-018535IN-MAL-2026-018527IN-MAL-2026-018518IN-MAL-2026-018514IN-MAL-2026-018515IN-MAL-2026-018530

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks @postman-cse/okta-aio-linux-arm64-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

@postman-cse/okta-aio-linux-arm64 (npm) malicious package — MAL-2026-14357 | O3 Security