Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

awaitly-visualizernpm

awaitly-visualizer is a confirmed malicious npm package (MAL-2026-5239) that steals credentials and exfiltrates sensitive data (malicious versions 1.0.1, 2.0.2, 3.0.1…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in awaitly-visualizer (npm)

MAL-2026-5239
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall awaitly-visualizer

What this malware does

The package was found to contain malicious code or consuming dependency that contains malicious code

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

The Miasma malware is a self-propagating worm that spreads across the npm registry by abusing weaponized binding.gyp files to achieve execution during package installation, bypassing security tools that only inspect package lifecycle scripts. Upon execution, the malware attempts to exfiltrate credentials and OIDC tokens for various cloud and registry services, and propagates by compromising other packages managed by the stolen accounts or committing backdoor files to GitHub repositories.

Malicious versions

22 flagged
1.0.12.0.23.0.14.0.15.0.16.0.17.0.18.0.19.0.110.0.111.0.112.0.113.0.114.0.115.0.116.0.117.0.118.1.119.0.120.0.221.0.122.0.2

Indicators of compromise (SHA-256)

a6c7977dbc054cdb7fe56da0d2fbd26e2a6fed695deb4263ccbf4adfedd86acb
b7f392622f2aeb9a1cd98719278777d45ea44442e6f3979175ed8d8b6f8a0389
1b8bb11505c3386790c84fb0aaa0ec908531a32ed760f2823f3002b554bee05b
2a4d675d23ada81ba065b755524a1dc414536b8b20c2b72c5deb5403d3253e8f
8744424670c459b9b8667bd8eeb1a50fcaa829e2daf5c63ef060b15d18b7182a
cef69d3730f2a325d51b68c712ff3f217601f36608708bd7b827dbf9f79f3b23
cef79e640f70f9c8c4816f69f2934f745b525789912e36238c6ebad15ec1d018
e2817b7e54288eb26236b7f28784a4fb25a473e0dea287c8713b9c7fe465bc33
925a97dd0b22d03dc128d155d093339d3499e6a0ca6de5c50571bb75f30f30a4
b0b30a2f2bbe177a9db14afc7adc562823122d4d723a3e4168fb4aea2aa5c86c
072151990ca7698ecc28bfa3fdd44d80dad2a33554b5c4cebcd5cbc6588e511f
08560dc1d03a88e5fa540c676941c6cdcf6f9ae9f62ef4e15aad54ecc3d8d852
32eaafc79525c89aff1be53eb64b1d304781d9bae904b562104aa41fad4b74ca
55a0d627a93083caa8c104de816de2d7482eb1215ae7efe9d87929b246816040
684bb8d654e25390008a7eeafa492c3d6e70911c7ee016ca5e722ef6774b0eec
816dd4e0cccc4d51f1345e57aba4f573c00570783a052fe85adf6956abe2bbf7
2f787a5f1c886c8266deb515c9b6f46cb374598db7a77e47225438b98461efb4
59d62652efd7d7491d028d846a5cc51ad4bdfb7393c8d2267cf66b233e7ddeca
7d5841c225146106409739c5d60de74ed3fc1bf792e2b10d532a06d1df15284b
b7edb655cf04c49a8894482ca344daf822622875d38031dde1594c8ea04e68ca
f1d0b9862bded4424df40a6d5216114ac98bf732d704aa6ca1f467b0b5efaf23
2fe3463e78f43c975a3b2ff90d3fff58cf4fbcb4a396443ea8d2ae7634da0c1e
a7c7b10ad91e2cb7afefa5379716d430304cfbddb6cdc891c9678e773c90c879
781cde98472aad4ed10bd99da7d13e85429142818d1ebe395b7be8cd1dd9beeb

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for awaitly-visualizer (22 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging awaitly-visualizer across your stack and pipelines.

  2. If you installed it — respond

    awaitly-visualizer is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If awaitly-visualizer was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks awaitly-visualizer before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. awaitly-visualizer on npm has been identified as a malicious package (versions 1.0.1, 2.0.2, 3.0.1, 4.0.1, 5.0.1, 6.0.1, 7.0.1, 8.0.1, and 14 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-008394IN-MAL-2026-008534IN-MAL-2026-008539IN-MAL-2026-008532IN-MAL-2026-008407IN-MAL-2026-008538IN-MAL-2026-008414IN-MAL-2026-008416IN-MAL-2026-008543IN-MAL-2026-008401IN-MAL-2026-008417IN-MAL-2026-008391IN-MAL-2026-008535IN-MAL-2026-008541IN-MAL-2026-008356IN-MAL-2026-008536IN-MAL-2026-008537IN-MAL-2026-008533IN-MAL-2026-008412IN-MAL-2026-008779IN-MAL-2026-008770IN-MAL-2026-008754GHSA-7vwj-f8vf-q9jf

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks awaitly-visualizer-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

awaitly-visualizer (npm) malicious package — MAL-2026-5239 | O3 Security