Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

awaitly-postgresnpm

awaitly-postgres is a confirmed malicious npm package (MAL-2026-5238) that steals credentials and exfiltrates sensitive data (malicious versions 0.1.1, 1.0.1, 2.0.1…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in awaitly-postgres (npm)

MAL-2026-5238
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall awaitly-postgres

What this malware does

The package was found to contain malicious code or consuming dependency that contains malicious code

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

The Miasma malware is a self-propagating worm that spreads across the npm registry by abusing weaponized binding.gyp files to achieve execution during package installation, bypassing security tools that only inspect package lifecycle scripts. Upon execution, the malware attempts to exfiltrate credentials and OIDC tokens for various cloud and registry services, and propagates by compromising other packages managed by the stolen accounts or committing backdoor files to GitHub repositories.

Malicious versions

24 flagged
0.1.11.0.12.0.13.0.24.0.15.0.16.0.17.0.18.0.19.0.110.0.111.0.112.0.113.0.114.0.115.0.116.0.117.0.118.0.119.1.120.0.121.0.122.0.123.0.1

Indicators of compromise (SHA-256)

a6c7977dbc054cdb7fe56da0d2fbd26e2a6fed695deb4263ccbf4adfedd86acb
3015c3afc4f26f62482274726cb1ce34f803abd4b7e84a6eb7e0c802e8c8b7df
3fc0868e68b643e3920c542f2c8e6e1b66f93ce402e89e8a61bf0965eb6fb307
410102526b482ab821de1d2da059c014e33a5164ee688b8d7b85f9d2c1b9d346
7d0d4b1d4c4a22cc4596e7da206dca99b8e4d970db7795ef410806c7585737cf
8e50ca715bc5c97615dff033c9024dd4ed5db64f141d33a4a78392f5c83fb5b0
afa5228c052b99e5f377677754264e51fd5f0aba479187017a8ccfa9919c9238
ba4c5b44fcb34d3bffd4d64bf3977bd651c6ca61580783620c4e300585dac732
e44cc2da488672d5b989a23dc9bceab8b78ed4ccfa832f461cb72f4b73ec3d92
1181c89370eddf2cba040fcab543143b87f36658155665f16b54c966c14fc45c
20e2d3c313a3212f4e9a0cb8eff05ad45dfd4ad6f89fd9dc0f5666267ef6fd68
57409887edc79d5ca1f251c41b49053e69c1f269e1e797faacafea0323095e88
b9856fb864944b7552b41f53014723ef7d772b79596e6e7c7f2af30939508137
64a3fad865a31eea19ef0b0c1882e622f8ea9f14416efc7cd00a11397b1baaf4
1dd220ccef97419241d4b00f2e7cd6b1544c5db50f9eddfeb45716770a497e20
20e6c799ccdd4c3b02260b186a0ba01aad4e4224f9c3cad6a8f9593d9668947e
2a7724becb41ae1756ffb8ab0a1e391f28df6424f50ab7c9fe9571bd39faf072
8bec48c3d2ab2a9f4c6795e272f36b0cde33702937b473ccea116eb0aa3c5dbb
bec834edc573d4f947800086b5c7a3a4c25939b78934cdaae40afa53d26d7f99
23586addfedfa1b7018f3d59e7bd112a4b6b40c4cd8a58c3272f24c059f5c2cb
4c3b7b934e806c680c4bd07f5c67fa5032a70b7b0272523763479f18726a7296
4fa4190dcdc9240a42d72d29b2056ce9e8d22486ff1c1149a573eb074c3222d1
a7a2e77140d8ff4f8d6d64280975968b0271f4595eb3f416b022dfa3a0f65d7a
eda2f7506979f835f5afa0bf0f2007445af3e4cf08728748e92b6e19108dae09
fe50c6ce74352ac7e249f61c341eca94d206b9cf892bcddf2876d572adc8822e
9e31bda92c158dc62c0b65eab8efb970077f4c26baaa88f3ae0a01d1bb3924b8

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for awaitly-postgres (24 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging awaitly-postgres across your stack and pipelines.

  2. If you installed it — respond

    awaitly-postgres is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If awaitly-postgres was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks awaitly-postgres before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. awaitly-postgres on npm has been identified as a malicious package (versions 0.1.1, 1.0.1, 2.0.1, 3.0.2, 4.0.1, 5.0.1, 6.0.1, 7.0.1, and 16 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-008542IN-MAL-2026-008529IN-MAL-2026-008522IN-MAL-2026-008528IN-MAL-2026-008450IN-MAL-2026-008545IN-MAL-2026-008524IN-MAL-2026-008523IN-MAL-2026-008526IN-MAL-2026-008449IN-MAL-2026-008525IN-MAL-2026-008448IN-MAL-2026-008718IN-MAL-2026-008745IN-MAL-2026-008761IN-MAL-2026-008768IN-MAL-2026-008760IN-MAL-2026-008769IN-MAL-2026-008749IN-MAL-2026-008742IN-MAL-2026-008746IN-MAL-2026-008737IN-MAL-2026-008772IN-MAL-2026-008747GHSA-hpp3-2qqp-gw63

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks awaitly-postgres-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

awaitly-postgres (npm) malicious package — MAL-2026-5238 | O3 Security