Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

accounts-final-formnpm

accounts-final-form is a confirmed malicious npm package (MAL-2026-11504) that executes malicious code on install (malicious versions 0.0.1, 9.9.9, 9.9.10…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in accounts-final-form (npm)

MAL-2026-11504
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall accounts-final-form

What this malware does

Requiring accounts-final-form auto-runs setup.js via process.nextTick(bootstrap) in index.js. setup.js selects a platform-specific asset path (/pkg/package, /pkg/package-arm64, /pkg/loader_mac, /pkg/package.exe), fetches it from a list of obfuscated Cloudflare Workers hosts (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev) with DNS fallback to *.dl.well1.site, stages the file under /var/tmp or %TEMP%, chmods it 0755, and executes it via child_process. Destination hostnames and dangerous APIs are constructed by string-splitting and.join("") to evade static analysis (e.g. require("child_"+"process"), os["plat"+"form"], fs["chmod"+"Sync"]). setup.js additionally computes an install fingerprint from os.hostname(), os.userInfo().username, process.cwd(), process.version, and process.pid, hashes it to 16 hex characters, and sends it as installId in the request to the same Workers hosts, enabling per-victim identification. The package's advertised purpose is a vacuous "Accounts final form runtime support module" that does not justify pulling native binaries from anonymous workers.dev subdomains and executing them.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

7 flagged
0.0.19.9.99.9.109.9.119.9.1212.5.534.2.5

Indicators of compromise (SHA-256)

3119fb8dbf1b8a8b5c69c7fd4212673ce6a7d2c52c4fa06a7a498e97c15897f0
388d468461310c1f7dd27e857ecd6658f335ea39a7b108155cf1c0f87315a548
7083822c9ddeb6927832ae4b86e8f910984ebde1e61c9374e31f75e90f63052f
a7e67b952090179c0e7ed57045bf117d0cc14ca7d832ddce2963c4f2049b66bb
b3a985ec139a2b660793e6cdebff7ec67ecf6e154b95c5a4491d89cf26978417
b4cd5bacab73e03f698ff9d279e4ecde6def4ff9248851bd538918cc91a6c58d
f0838440aeee0503d74a380c2286df06ebea6644b5d3a7cdca3b97268731573c
8ec9cbaaaab07b219ce60fa0191417968e62f49a4a02b56bd0758af1c15caa01

Detection & response playbook

Malicious package
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for accounts-final-form (7 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging accounts-final-form across your stack and pipelines.

  2. If you installed it — respond

    Remove accounts-final-form from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If accounts-final-form was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks accounts-final-form before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. accounts-final-form on npm has been identified as a malicious package (versions 0.0.1, 9.9.9, 9.9.10, 9.9.11, 9.9.12, 12.5.5, 34.2.5 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

GHSA-2rrw-8g3r-w44hIN-MAL-2026-011036IN-MAL-2026-010992IN-MAL-2026-011038IN-MAL-2026-011040IN-MAL-2026-011041IN-MAL-2026-011039IN-MAL-2026-013133

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks accounts-final-form-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

accounts-final-form (npm) malicious package — MAL-2026-11504 | O3 Security