Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

ai-texts-utilsnpm

Advisory published Updated

ai-texts-utils is a confirmed malicious npm package (MAL-2026-14302) that executes malicious code on install (malicious versions 1.0.0, 1.0.1, 1.0.2…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in ai-texts-utils (npm)

MAL-2026-14302
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall ai-texts-utils

What this malware does

[email protected] declares a single runtime dependency, 'ai-texts', shipped as a bundledDependency inside the tarball. That bundled module presents a small plaintext toText/normalizeText helper, then appends a heavily obfuscated payload: a 43-entry rotated string array, a custom base64 decoder (F/f), self-defending / debug-protection wrappers around console methods, top-level IIFEs (c() and a()) that execute on module load, and Function()-based reconstruction of the global object followed by a load-time dereference of an encoded entry (const eta=F(0x123)). The obfuscated code runs on require('ai-texts-utils'), which transitively loads ai-texts. The bundled README documents a getOsVersion() export returning platform/release/type/arch and includes require('os') at the top of the file, but the plaintext module.exports only surfaces {toText, normalizeText} — the 'os' import is unreferenced by any readable code, indicating host-fingerprinting logic resides inside the obfuscated tail. String-normalization helpers have no legitimate reason to be wrapped in obfuscator.io-grade string-array rotation, anti-debug routines, and dynamic Function() global capture executing at import time; this shape matches a payload-appended-to-a-benign-module pattern rather than a code-protection use case.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

4 flagged
1.0.01.0.11.0.21.0.3

Indicators of compromise (SHA-256)

a340348046b89bf8c446a31a4f48233ec4e0bc412f531db713f54f35c6ea922c
981d46d97825c6c05b670b060d4842c7b42a87371746abfae09e6d619312111c
0444a2179f1067853015cb382e426c1a77fe8c3fb795afbe6b1737c4b2bcdf49
8b332f7e86aef546ca6340e675c75ca16d55cdfe9bbb7ececd583efe3c114645
f4c833aec11aaec0f3e51fd47aee3a4487341dd92701e51cef3e52161b5314e1

Detection & response playbook

Malicious package
  1. Find it

    Search your lockfiles and build artifacts for ai-texts-utils (4 malicious versions).

  2. If you installed it — respond

    Remove ai-texts-utils from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If ai-texts-utils was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.

Frequently asked questions

No. ai-texts-utils on npm has been identified as a malicious package (versions 1.0.0, 1.0.1, 1.0.2, 1.0.3 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-018423GHSA-3p3q-38q9-rr37IN-MAL-2026-018443IN-MAL-2026-018447IN-MAL-2026-018446

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks ai-texts-utils-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

ai-texts-utils (npm) malicious package — MAL-2026-14302 | O3 Security