Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

@card-pci-data/storenpm

Malicious code in @card-pci-data/store (npm) Remove it immediately and rotate any exposed credentials.

MAL-2026-5407
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall @card-pci-data/store

What this malware does

On npm install, the package's preinstall hook (scripts.preinstall: node index.js || true) runs index.js which collects host identity — os.hostname(), os.userInfo().username, __dirname, and process.cwd() — and exfiltrates it through two channels: (1) an HTTP POST to the hardcoded bare IP 172.201.213.59:9090/c, and (2) a DNS resolution of a hex-encoded label appended to *.d8jbmnsqcfu78dfs8vdg34ohqhirb4pbg.oast.live (an interactsh-style out-of-band beacon). The package has no advertised functionality beyond this beacon; its description is security research and the scoped name @card-pci-data/store impersonates payment-card / PCI-related tooling, consistent with a dependency-confusion or namespace-abuse lure. This auto-executes on default install and produces clear attacker benefit (installer host fingerprint delivered to attacker-controlled infrastructure).

Malicious versions

2 flagged
99.0.099.0.1

Indicators of compromise (SHA-256)

33b09478f47cfd67351be7f721c43e09b762c10c8a906841cfbd23831402545e
9a82d7b7e7588c4b773e2948eb1707e62f2fcece2bec37a23eda5d5058eae871
779786fd07ed03346ff0fac4649d39b7d75f0e02269dda4247843e6b5fa409b3
4665eb8e66828c47db4912fce66beb3d7a30609a37a48a81d6010d796ba4fbf6

Frequently asked questions

No. @card-pci-data/store on npm has been identified as a malicious package (versions 99.0.0, 99.0.1 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-005079IN-MAL-2026-005078IN-MAL-2026-005147IN-MAL-2026-005146

References

Credits

  • Amazon Inspector · finder

Scan your dependencies

O3 Security blocks malicious packages like this at install time and in CI.

Supply-chain protection