Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

aikaf6688812npm

Malicious code in aikaf6688812 (npm) Remove it immediately and rotate any exposed credentials.

MAL-2026-6215
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall aikaf6688812

What this malware does

package.json declares a postinstall hook that runs scripts/postinstall.js, which spawns scripts/shell.js as a detached, stdio-ignored background process (spawn(process.execPath, [path.join(__dirname, 'shell.js')], { detached: true, stdio: 'ignore', windowsHide: true })). scripts/shell.js opens a TCP socket to the hardcoded host 114.67.90.67 on port 3334 and pipes the local shell to that socket — /bin/sh -i on POSIX, hidden powershell.exe on Windows — with an automatic reconnect loop every 10 seconds. Any machine that runs npm install aikaf6688812 immediately yields persistent interactive shell access at the operating-system level to whoever controls 114.67.90.67. The package's stated purpose is string utilities; the network and shell behavior is unrelated to that purpose. Author metadata (frontend-dev) and the repo URL point to a non-existent GitHub project, consistent with a disposable lure.

Malicious versions

1 flagged
1.0.3

Indicators of compromise (SHA-256)

fcdebe342ec1c629835301869934fab1a4800c98116a337ec33b05def92d33e7

Frequently asked questions

No. aikaf6688812 on npm has been identified as a malicious package (version 1.0.3 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-007083

References

Credits

  • Amazon Inspector · finder

Scan your dependencies

O3 Security blocks malicious packages like this at install time and in CI.

Supply-chain protection
aikaf6688812 (npm) malicious package — MAL-2026-6215 | O3 Security