Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

@whalent/agent-corenpm

@whalent/agent-core is a confirmed malicious npm package (MAL-2026-10722) that steals credentials and exfiltrates sensitive data (malicious versions 0.3.230, 0.3.231, 0.3.232…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in @whalent/agent-core (npm)

MAL-2026-10722
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall @whalent/agent-core

What this malware does

The package's main/bin entry (dist/index.cjs) implements a remote agent that opens a WebSocket to a gateway configured via WHALENT_GATEWAY / WHALENT_TOKEN / WHALENT_PLATFORM_URL and, over that channel, drives local PTY sessions via node-pty, spawns shells against process.env.SHELL, bridges loopback services on 127.0.0.1:3389 (RDP) and 127.0.0.1:5900/5901 (VNC), and runs a Python Jupyter kernel sidecar (dist/jupyter_sidecar.py) that executes arbitrary NDJSON-delivered code cells. The remote party at the gateway therefore has interactive command and code execution on the installer's host, plus a channel to reach otherwise-loopback-bound RDP/VNC. The 13.6 MB dist/index.cjs is protected with obfuscator.io-style transforms — a rotated 105,426-entry string array, _0xNNNN identifier renaming, decoder wrappers, and control-flow flattening — hiding the gateway URLs, command dispatch, and upgrade logic from review. The bundle additionally contains an npmInstall code path plus WHALENT_NPM_REGISTRY and WHALENT_CORE_ENTRY environment configuration, and the README describes the package as one that is 'replaced by remote daemon upgrades', so the running agent can be instructed by the gateway to fetch and swap in a new version of @whalent/agent-core from a configurable registry, executing whatever code that fetched artifact contains. The net effect of installing and running this package is a persistent, remote-controlled RCE channel into the installer's machine with a self-update mechanism that can pull further code from a registry the remote party can influence.

Malicious versions

49 flagged
0.3.2300.3.2310.3.2320.3.2330.3.2340.3.2350.3.2380.3.2390.3.2400.3.2410.3.2430.3.2440.3.2450.3.2470.3.2480.3.2490.3.2500.3.2510.3.2520.3.2530.3.2540.3.2550.3.2570.3.2580.3.2590.3.2610.3.2620.3.2630.3.2640.3.2650.3.2660.3.2680.3.2710.3.2730.3.2750.3.2760.3.2770.3.2780.3.2790.3.2800.3.2820.3.2880.3.2890.3.2910.3.2940.3.2950.3.2960.3.2970.3.298

Indicators of compromise (SHA-256)

46be592c948ce3d8346e8df384e2925b3d3d6011079b1033257395bc6f989f4e
96088bf0c797b908d17f5ac937e019a9c65a8f7c02a9fe5d78e32b2dc5f64e8f
dfa859fe59b5a5e6139dfb586748a1a49a1dbf95e1a4df9dd9360d54e358b632
dfd40ffe52986a560961c8d4d9d7a3ec526813f9a2f335cef9c6884ca9f6d2cf
811508b0151874b0105b396a1ad5993b7fee5015742b2b2220034eb3d93236a1
14e7971e9132b8243ba12fcf61d6b749718c88e9c02e02f15471f721fe207bcd
3107f0284317014c3df66adde3086c9294b6207256d5404e9279787ae6f81667
90cd4fdc6d2a722921a9714c3cac69493db464a3c7e8a8a31ba12f1b5df2ad1d
be658feb838b7653a7563627c0e7b80f41e91487c0a9b950e8062790d84d6978
67e27f60a9673ab2e9676369114606e6b5757f3825969dee8d4b9b0074e3b54b
7692218c096e4d081c0d4721255046c02675b8e7a576c0d753e1a6308e8f3606
9017aac5656f4105fcfcf2984f6eea0cea4b131579ca385b1e7c6ea5d4dc11cb
dc36f896d7d48928de1f657993ed80fb8cf729c12e96b4556b851e6b7515389d
e02004353541b138d2453fb599789749f235a45c1da87578e2570959807b146c
20ae409525f897a6bf13470423151c019808ababcc9455c1357dd7a0f26133ad
63c0b08b0ef2d85b4cd3d7c71dcbf77fe7a2b9f760809ce02d0dd1e5c27bda6d
7921089093342b0425ada24f1454c86bd0abf8273bcd7e249a1f50b8d476eb49
84fff48eeb751d773ce91e440353fe03e2574234047a4c77de7f86a3a5755a15
c9fc0fbee1fdeb89486d7662d5ab11c095ae9b5244e5c8352c7a4951ad25f746
2cf17de651aab9a6dce831fd09935b61ef2dffc389e8424ac28045737e1121f6
40a21e4cec6d3659c3887cac58aacb824e3f029cbf0dcfb67fcd59384a3d1539
7c1a4e8bd6dc6eb76f7a30de424b0d6ca77aeb7894f7c8fa7272eea08c1a91ae
fdb6b1fc231c90a2e858c93ec86b4450aaa47802e1dafd19dfc0468a70e59411
152fd75b4369c54ada8784514bc26ebccaa9b17f5fd2c27d1983e46bc312d82e
670458226a629127508676f55312dbc6129b865315d77e66eccc02dffe9454fc
9e1b877e9a34e5ac9d87ff0be3b79c35ee81554b75caec48631a94cac57f1a28
ab5ffafd216bc18c498742c4a24c80cc167f27f5e002cc3192a3a5b23e906899
c5c5d74ab460a6011b6fc4125744a380b5a6dbda904c6ef4ea87921f9b7e3eeb
d8865ae7d25a498766280337f12ceea445a92bd6a6565e668651a79dbcc152e9
f3661b57629a28ec3c727257a68c239f071fd355af0a9193371b958bb4e365ed
2ad557e95ad107b801c5025dfe6df4a7557ecfeb7a067ced1899a5e18af87e9f
427d08ffc5069e53bf44cb776a2031107b51642946e0afc98a5773ea77bb66d3
42d84ee02db23fc5f3a144e79e44d2baced3966000e533bd6a9ce6dc766ce6ec
7221e74b8b8f3c7b271ce4870c1a11b04119eb043f5b9154da8e3eb5f6c0434c
747b4ea4b26831b1472eb1fed85d7e5de73f82da9297661da3dd0380341518b2
cd61157fdd8757783087e6e36ec9e6f26b57c6ef2c9a67d3f3ded4863e27aedb
e1eb06c3a520c0c6a0ca155821dcdd466ae392519f550fec2951f788d9d557ce
f4749bcc3f267bed496c864419c8aea50c7da89778bf40a0db7c29587ae22911
61fa518c11906647a6c6b85c1a63f6cb64331b29395b00c984562c74ca2bce62
854343cc54b4886963723dfc7bb22a01b5b785cec17792e1a96945d4bfde62e3
d196c84a8abd7bb3c0c7bc5f4ef5c44b673101c0688ede0354a91487d21ff9b1
ee2bbf0621f845b3c6a2f0e81cffdf3d9d5bc9f864f980a4ed0a3399d0574c70
a734409d9b32151ce01007b7393327e8f424aa9e3ce25269a57fd473a9a4b793
0cf38e885f27ac7b85d4e80ed6219791d994c1dd03b58746cad18c4445455f93
88f2f39be4b0537b33881bd4b65fea4502d17ed4cbdb3f9621839e6047310270
a44db0d52ec24be996ea81ad7451041e683d0350da9c7df7e0db5c1140f1586a
b5ddda891167c7ea6944c17795818a343098a5eb9e4e9572db99ee3e38c71f5d
b5e4230c0446c5ec41494d6f59475a851d4cc3efc81432addb7bf9ba33290f2c
c41404d18abdaada9f5dfaa1f9edfcc2e9235ed1abce2dd291d414cf531fd758

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for @whalent/agent-core (49 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging @whalent/agent-core across your stack and pipelines.

  2. If you installed it — respond

    @whalent/agent-core is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If @whalent/agent-core was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks @whalent/agent-core before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. @whalent/agent-core on npm has been identified as a malicious package (versions 0.3.230, 0.3.231, 0.3.232, 0.3.233, 0.3.234, 0.3.235, 0.3.238, 0.3.239, and 41 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-010759IN-MAL-2026-010756IN-MAL-2026-010752IN-MAL-2026-010744IN-MAL-2026-014795IN-MAL-2026-015924IN-MAL-2026-015911IN-MAL-2026-015914IN-MAL-2026-015916IN-MAL-2026-015930IN-MAL-2026-015928IN-MAL-2026-015921IN-MAL-2026-015931IN-MAL-2026-015912IN-MAL-2026-015934IN-MAL-2026-015935IN-MAL-2026-015909IN-MAL-2026-015915IN-MAL-2026-015918IN-MAL-2026-015933IN-MAL-2026-015919IN-MAL-2026-015929IN-MAL-2026-015973IN-MAL-2026-015962IN-MAL-2026-015953IN-MAL-2026-015968IN-MAL-2026-015944IN-MAL-2026-015952IN-MAL-2026-015960IN-MAL-2026-015947IN-MAL-2026-015950IN-MAL-2026-015981IN-MAL-2026-015967IN-MAL-2026-015945IN-MAL-2026-015941IN-MAL-2026-015939IN-MAL-2026-015940IN-MAL-2026-015980IN-MAL-2026-015951IN-MAL-2026-015974IN-MAL-2026-015963IN-MAL-2026-015978IN-MAL-2026-015984IN-MAL-2026-015958IN-MAL-2026-015983IN-MAL-2026-015948IN-MAL-2026-015955IN-MAL-2026-015970IN-MAL-2026-015975

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks @whalent/agent-core-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

@whalent/agent-core (npm) malicious package — MAL-2026-10722 | O3 Security