Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

9remotenpm

9remote is a confirmed malicious npm package (MAL-2026-13406) that executes malicious code on install (malicious versions 2.1.1, 2.1.5, 2.1.6…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in 9remote (npm)

MAL-2026-13406
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall 9remote

What this malware does

9remote is a remote-shell tool: its CLI launches an HTTP/WebSocket server and provisions a Cloudflare Quick Tunnel that exposes the host to the public internet at a 9remote.cc-fronted URL. Incoming WebSocket input messages are forwarded verbatim into a locally spawned PTY (bash/zsh on Unix, cmd.exe/powershell.exe on Windows) via pty.write(s.data), after spawn(o.path, o.args,...) in the pty daemon. The server's router treats requests bearing the cf-connecting-ip header as remote-authorized. Access is gated by a short-lived (~30-minute) one-time pair key shown as a QR code; anyone who obtains that key over the tunnel obtains a full interactive shell on the host with the user's privileges. The package is invoked explicitly by the operator (bin entry, not lifecycle scripts or top-level require side effects), and the tunnel terminates at first-party infrastructure (9remote.cc / Cloudflare), so this is the advertised behavior of the tool rather than a covert channel — but the blast radius on any host where the CLI is run is full-host remote code execution behind a single short-lived key.

Malicious versions

10 flagged
2.1.12.1.52.1.62.1.92.1.142.1.162.1.202.1.212.2.52.2.6

Indicators of compromise (SHA-256)

176c0f836027b6464583c707e532c2f8776dc299763837f3d0979aeb34ee34b3
22a4e5c39f7a943e2cc2baef9292bc7bedd55600bddf5c829dcc8076211fda3b
4160b2e2774d56c9e7373db28a4073d456248d0fe9b55979fa507f0910b65ce0
50ecf084f7adfa9c742234b8137a3725ec71728b254950efe2b630c0e4cf57a8
7017db3f7480a7357c78587e7d6f5ff85fcd3ccfc316f575fc17e60c20d5c592
f0c4686e0ed2e8e4e8031eb4cc5618ade0e9be4885039d981132ad9b10637754
342eab2cbe8adf419d7f9f08116929689111deef4595ce231b52e9e30aaabf1b
348253e1e3b9ef12096655a25242b519780e85085f1c257c982a61caa64ab020
47e410f8e3224069a52d658deb957bf5b5038a3b46123071a411f042470109bb
5dc6eeb1739454cc986c504bdd701856a793eaf823057761fc9133cf5234b3b2

Detection & response playbook

Malicious package
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for 9remote (10 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging 9remote across your stack and pipelines.

  2. If you installed it — respond

    Remove 9remote from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If 9remote was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks 9remote before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. 9remote on npm has been identified as a malicious package (versions 2.1.1, 2.1.5, 2.1.6, 2.1.9, 2.1.14, 2.1.16, 2.1.20, 2.1.21, and 2 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-016372IN-MAL-2026-016374IN-MAL-2026-016370IN-MAL-2026-016377IN-MAL-2026-016376IN-MAL-2026-016369IN-MAL-2026-016373IN-MAL-2026-016378IN-MAL-2026-016375IN-MAL-2026-016371

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks 9remote-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore