Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

autotel-devtoolsnpm

autotel-devtools is a confirmed malicious npm package (MAL-2026-5218) that steals credentials and exfiltrates sensitive data (malicious versions 0.1.1, 1.0.4, 2.1.1…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in autotel-devtools (npm)

MAL-2026-5218
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall autotel-devtools

What this malware does

autotel-devtools ships bundled CommonJS and ESM artifacts (dist/cli.cjs, dist/cli.js, dist/index.cjs, dist/index.js, dist/server/index.cjs, dist/server/index.js, dist/widget.global.js) where pattern matches surfaced co-occurrence of Buffer.from(..., 'base64') decoding alongside HTTP POST and 'ping' tokens. The package is presented as a developer-tools CLI/server, which legitimately bundles command names and HTTP clients into a single rollup output, and the matched primitives are consistent with that shape (e.g. base64 token decoding, POST against a configurable backend, a 'ping' subcommand or health-check string). No specific attacker-controlled destination, env-var scraping, credential path read, or install-time lifecycle hook was identified, and the keyword proximity inside minified bundles is the weakest evidence shape. A human reviewer should de-minify the relevant spans around dist/cli.cjs:534 and dist/index.cjs:143 to confirm whether the POST destinations are user-configurable backends or a hardcoded endpoint, and whether the base64 decode handles a JWT/session token or executes decoded bytes.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

The Miasma malware is a self-propagating worm that spreads across the npm registry by abusing weaponized binding.gyp files to achieve execution during package installation, bypassing security tools that only inspect package lifecycle scripts. Upon execution, the malware attempts to exfiltrate credentials and OIDC tokens for various cloud and registry services, and propagates by compromising other packages managed by the stolen accounts or committing backdoor files to GitHub repositories.

Malicious versions

8 flagged
0.1.11.0.42.1.13.0.24.0.15.1.16.1.26.2.0

Indicators of compromise (SHA-256)

a6c7977dbc054cdb7fe56da0d2fbd26e2a6fed695deb4263ccbf4adfedd86acb
1d9ead83772087e781dd41428b81aec15c104b5064f20f0c47e911025942bd01
290f74e8db7c8387afb1546eb5dff62a089401c697edb9133c44780b657612f8
452af7307b36895451450caf150c691da5b77a569bf725ca94de24c087519db2
4a25b8d8733e735f7b5d9478cb5420c2cef93ae7dd820d4f093878bfe9466be4
5642b46af3cbbdebef3cbeeb5d8663c7ceca322801af025bfb18f7cb46474891
96bc6fce6ff93785cf2bd81cbd54348bcaa4df68c01e8d1374bb192bd2fb6b90
dbcc2077a3be43d3864137c99297685f0817f0729d8c8ace690ad00abf35a508
e1bce8c001a8e85b493ccdd8af1e3e57f3578d1026e6d5d147374b0a68467313
737ba7512d8ab67dc3c28109beb7cd49581393025def1b9d4d7ac9ce0a5f9a3b

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for autotel-devtools (8 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging autotel-devtools across your stack and pipelines.

  2. If you installed it — respond

    autotel-devtools is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If autotel-devtools was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks autotel-devtools before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. autotel-devtools on npm has been identified as a malicious package (versions 0.1.1, 1.0.4, 2.1.1, 3.0.2, 4.0.1, 5.1.1, 6.1.2, 6.2.0 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

GHSA-r65m-xcg9-hvfhIN-MAL-2026-008663IN-MAL-2026-008666IN-MAL-2026-008660IN-MAL-2026-008647IN-MAL-2026-008649IN-MAL-2026-008657IN-MAL-2026-008653IN-MAL-2026-009538

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks autotel-devtools-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

autotel-devtools (npm) malicious package — MAL-2026-5218 | O3 Security