Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

@whalent/agentnpm

@whalent/agent is a confirmed malicious npm package (MAL-2026-10721) that steals credentials and exfiltrates sensitive data (malicious versions 0.3.230, 0.3.231, 0.3.232…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in @whalent/agent (npm)

MAL-2026-10721
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall @whalent/agent

What this malware does

The package installs a whalent CLI daemon that opens a persistent WebSocket connection (wss://) to a Whalent Memory gateway and, per its own README, accepts remote commands including 'upgrade' and 'restart' from that gateway. dist/index.cjs contains an npmInstallCommand builder that assembles npm install -g @whalent/agent@<version> --registry=<DEFAULT_NPM_REGISTRY|CHINA_NPM_REGISTRY> strings driven by the gateway's chosen version — meaning whoever controls (or compromises) the gateway can cause the daemon's host to install and execute an arbitrary version of the package as the user running the daemon. The core bundle additionally references process.env.SHELL and localhost RDP/VNC ports (127.0.0.1:3389, 5900, 5901), and the dependency set includes @xterm/headless, node-pty (optional), ssh2, and ws, indicating terminal/PTY and remote-session capability reachable from the same gateway channel. Both dist/index.cjs (main/bin entry) and the 13 MB dist/core.cjs are transformed with javascript-obfuscator (string-array rotator, _0x-named helpers, control-flow flattening), and javascript-obfuscator is listed in devDependencies — the obfuscation covers the gateway command dispatcher and shell sinks. The daemon fires only when the operator explicitly runs whalent --token …, not on npm install or on require(), but once running it provides a network-reachable code-execution and shell surface on the host controlled by the gateway operator.

Malicious versions

41 flagged
0.3.2300.3.2310.3.2320.3.2330.3.2340.3.2350.3.2380.3.2390.3.2400.3.2410.3.2430.3.2440.3.2470.3.2480.3.2490.3.2500.3.2510.3.2520.3.2530.3.2540.3.2550.3.2610.3.2630.3.2640.3.2650.3.2680.3.2690.3.2720.3.2770.3.2790.3.2800.3.2810.3.2820.3.2830.3.2850.3.2910.3.2950.3.2960.3.2970.3.2980.3.302

Indicators of compromise (SHA-256)

0d9a3395e3bbc1bae774ea99bb4100a3db071a6b4527eaba0ae9089eb51bf268
fc9f1353dd1babb9c60ebc986caa84ffc82882b0921aa11c995b78115b1831ec
4d12514948b86d764b8828c54da52db3244e1d32c15822732080a8705686c0dc
553c3c9ae96a853c5d3a49ca66416b51a19d0bd294822defd0df17a5ad730b2d
f059b944ebbb2201e187717af8c1ced2094523e0cfc422c317cb0b2f73a55efd
ff77fe438b3c498e663f632745ad49fdd123b606e2668812745587553d83aa2f
ff7f073fcc9c9de06e5c948f467500633311cf9d69631c774e62c385c687d069
054a3b27608efc3b6046ba900250b63f649d321d68864e03c77c4202ee41448a
0dbf05a1e7d0d675731ac8c0fdef41559cb2b17e410d813f99fad51aa1558287
0ebc433777a6ed727cb390ea43f1c82503392a23183778302aab0c05705b53a8
1ee6fbcdfd260d01d4728ffaa358c4c00b0dd2e731efa5c7e13bc18a68bb573d
2290c129b9b8945e34dd008a13a6bd4ee82b66d9be831b810e3d165d92eae5fc
8b762d1e2538fcc3a53e85ab0274dc6f3bde2f37f19b1d761f93130f86baa2b6
f862750d3f0716c770f107a2afe93ddaa40911f6f48d16321db8d94aaeb15f45
4eefc57ee5420b206ad8e11af7bd2a9672179b2ae9c241eb10454a28cf1a64b8
83d40295cc196e560a165974bdcc904456a3bcab856403a693797306490375f1
895d90f479cebc5a5d33aa417aa370e3694190cfb6287da27e4979e268d8ac8f
8ed957d4942ccccb6e4e7a08d70aba6305a6c47ec18992decfb5526324bd3c3a
90466332f58b17a0b4eae1aa65639029736d4f2d7021644e0ac4b158fa76fb8c
966bf296bb0b058366d848362f37c4fd26ea51bd26819ed08821f79fffb1f7af
13a01c1162adb93d3960d9e1b1b67095dcf0a1ea72aefa6d471d0abbbabb5d9a
183a5929f09b6d62afd0ca5e8c06e6d12eb05e8ac8488139daa97affde9e5dfc
e00560d5a7b4a8793a416a65deb7c9db34b30b6e57c0971b71724038cd7dab4b
e4e8676772d9460bc79d4a5e0d494349dcc141bdd9fd7cf7bf63b9841aaa108d
0aa95c21db0e80af982a98996b0ce0840da58f58071e05894780d6f4b9580ac9
1e892f2936e3527e3908ef5ab9fdf3f144fd5f4d9823963b8d6b71db5864a142
2f81deb87d31cd0f08d5d87a09f4104a2b9b858b94e1418be1394f94d3b9d3f9
3774078bdb40c185c056183187a8694db268269601d266441f5b5c8e76080d45
3aca42738f971bd3edffbe5cad924460cafe0814733fb5d78292be09de4827b1
bda9dace78866f9b37922722b4b6ceb716edcc340f4f760ad00ea0a3be1bdfb8
26b4c4d778c8faa85c5491b3a866ea984294bf79317b0e576b057f48c78d691c
78977bcb4e65b2897a4b13e97090d74c75c51e8f76fe22c2c544f8963140b465
8f0f30f53e8a6a61aebdfdf0c80ac0295acaa8fc3f1b441b4f5ed96ddfb3535e
9468ce68e595cdebd7a6ae02d12dca1053e22ea2df05d9ad88f0dc38b61ecc25
a69dde8063b2360d69ab3c87d2c95b015dffef0e6d2f60fc457f57e87a0154cf
abd1d06a175c56825c7a38ce77fb9fc38bf03c246f259ed9c681edbabc8fbbdb
cd7401a05d69a7a558ccb4813d1906f3ce80884e57dfc181ea9a76bbceec2f3e
db9a806b1b1d6ae806ed8bf735fec2a7e4a9e852a2c990d3d366db7877678053
046e44af467bf9f9451b532da22a71d193ac97213f042ad217927558e8100209
33f3732b67fc26c62344381cb3c0d8890b90c1999656363e26c9f41e1ab1c083
1ae150ffa9ddc01d96f5f58c49deb2fd8a4cbcdc0c0e7533ef970a36c04d0b24

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for @whalent/agent (41 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging @whalent/agent across your stack and pipelines.

  2. If you installed it — respond

    @whalent/agent is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If @whalent/agent was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks @whalent/agent before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. @whalent/agent on npm has been identified as a malicious package (versions 0.3.230, 0.3.231, 0.3.232, 0.3.233, 0.3.234, 0.3.235, 0.3.238, 0.3.239, and 33 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-010776IN-MAL-2026-015923IN-MAL-2026-015913IN-MAL-2026-015922IN-MAL-2026-015926IN-MAL-2026-015908IN-MAL-2026-015932IN-MAL-2026-015910IN-MAL-2026-015936IN-MAL-2026-015920IN-MAL-2026-015907IN-MAL-2026-015917IN-MAL-2026-015927IN-MAL-2026-015925IN-MAL-2026-015959IN-MAL-2026-015971IN-MAL-2026-015937IN-MAL-2026-015943IN-MAL-2026-015969IN-MAL-2026-015961IN-MAL-2026-015976IN-MAL-2026-015979IN-MAL-2026-015946IN-MAL-2026-015972IN-MAL-2026-015987IN-MAL-2026-015957IN-MAL-2026-015966IN-MAL-2026-015986IN-MAL-2026-015954IN-MAL-2026-015982IN-MAL-2026-015965IN-MAL-2026-015938IN-MAL-2026-015949IN-MAL-2026-015988IN-MAL-2026-015977IN-MAL-2026-015985IN-MAL-2026-015964IN-MAL-2026-015989IN-MAL-2026-015956IN-MAL-2026-015942IN-MAL-2026-015991

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks @whalent/agent-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

@whalent/agent (npm) malicious package — MAL-2026-10721 | O3 Security