Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

accounts-loading-statenpm

accounts-loading-state is a confirmed malicious npm package (MAL-2026-11505) that executes malicious code on install (malicious versions 0.0.1, 8.9.3, 8.9.4…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in accounts-loading-state (npm)

MAL-2026-11505
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall accounts-loading-state

What this malware does

On require() of accounts-loading-state, index.js loads setup.js which schedules bootstrap() via process.nextTick. bootstrap() detects OS and architecture, then invokes lib/telemetry.js run() against a list of string-split-obfuscated mirror hosts (approximately five oob-worker.cfNN-XXX.workers.dev Cloudflare Workers endpoints) with DNS fallbacks under *.dl.well1.site, requesting platform-specific paths /pkg/package, /pkg/package.exe, /pkg/loader_mac, and /pkg/package-arm64. lib/telemetry.js decodes base64 response chunks via Buffer.from(chunks, "base64"), writes the bytes to a staging path under /var/tmp or the Windows TEMP directory, and sets the file executable with fs.chmodSync(..., 0o755) before running it. Host strings and dangerous API names are reconstructed at runtime from split-string arrays (["oob-wor","ker.cf",...].join(""), require("child_"+"process"), fs["chmod"+"Sync"]) to hide indicators from static analysis. Alongside the fetch, setup.js computes an installFingerprint() as sha256 over os.hostname(), os.userInfo().username, process.cwd(), process.version, and process.pid, and passes it as installId to the fetching runtime, providing per-victim tracking at the download endpoint. The package presents itself as an analytics/telemetry SDK; the download-and-execute pipeline is the actual behavior.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

7 flagged
0.0.18.9.38.9.48.9.58.9.612.5.734.7.7

Indicators of compromise (SHA-256)

c0ddeec4da1eabc1035eb7097d83c9aa42f6d37c44a73e3c7b04ddd61d7d6635
08a283d16c5ea035b67ea814a0c92184718bce4766aab5017331f3f1b2b81a85
309160a44ed2b7c3e252b7c49c049bb6aa33ca439ed25532f39e6d513af2b4e8
88ba6c9c2a99862d842bf518a30a86be7765e4db568105b6605e6c55bfa66bf2
ad2a37306fb4a344a4b222b2d4442b6a6a4963b138b8e2d2cb54997c0ada4f3d
ce1392cbe70efe490eb061f9fc80510bab239f513aca60cd3133185a1a8ba092
3d430e8d55d80c0cf747e6c04058e0bc90274cc943a0e6e15651924c90be46d2
7e81bee0d41e3badd54cdd3bea73de8673133725068d5da787ce61b6b05ebeb8

Detection & response playbook

Malicious package
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for accounts-loading-state (7 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging accounts-loading-state across your stack and pipelines.

  2. If you installed it — respond

    Remove accounts-loading-state from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If accounts-loading-state was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks accounts-loading-state before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. accounts-loading-state on npm has been identified as a malicious package (versions 0.0.1, 8.9.3, 8.9.4, 8.9.5, 8.9.6, 12.5.7, 34.7.7 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

GHSA-9pwq-f6rq-8q69IN-MAL-2026-011066IN-MAL-2026-011075IN-MAL-2026-011062IN-MAL-2026-011064IN-MAL-2026-011063IN-MAL-2026-011120IN-MAL-2026-013333

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks accounts-loading-state-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

accounts-loading-state (npm) malicious package — MAL-2026-11505 | O3 Security