Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

biklimasternpm

biklimaster is a confirmed malicious npm package (MAL-2026-13786) that steals credentials and exfiltrates sensitive data (malicious versions 1.0.0, 1.1.3, 1.1.4). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in biklimaster (npm)

MAL-2026-13786
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall biklimaster

What this malware does

The npm postinstall hook (node bin/biklimaster.js install --postinstall) prompts for UAC elevation and then reconfigures the installer's Windows host into a remotely reachable, attacker-accessible machine. createRdpAdministrator either enables the built-in Administrator (RID 500) or creates a local admin account via PowerShell New-LocalUser, sets its password to the value shipped in config.json (administratorPassword: "Hacker@1290"), adds it to Administrators and Remote Desktop Users, and hides it from the Windows sign-in user list by writing to SpecialAccounts\UserList. bikliwrapper.js then applies registry settings enabling Remote Desktop (fDenyTSConnections=0), pinning PortNumber=3389, disabling Network Level Authentication (UserAuthentication=0), and enabling non-consensual session shadowing (Shadow=2), and adds inbound firewall Allow rules for TCP/UDP 3389 (BikliWrapper-RDP-TCP/UDP). The postinstall also silently executes bundled unsigned Windows binaries (bikli-cli-installer.exe /S, RDPWInst.exe -i, which patches termsrv.dll via RDP Wrapper). Because the credential is shipped in a package published publicly on npm, every installer receives the same admin password — the README even acknowledges it is 'visible to everyone if the package is published publicly' and that the bundled Windows executables are unsigned. The net effect of npm install -g biklimaster on Windows is a hidden local administrator account with a known password on an externally reachable RDP endpoint with NLA off and shadow-without-consent on.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

3 flagged
1.0.01.1.31.1.4

Indicators of compromise (SHA-256)

1427081760f79ad3c1c52496752f4c1a783f6f46f26eb43d691cfea00ca55de0
16fe526cf29535e21a0d1c3206405e20d0447ca01f25ea46dc9569ab52066555
7355d4fd8d99e36e38951c22724c673e0883a80ec116125c44a1ae50c6821580
a6e25cf4b46cb7e524919a742aa9a0eb3ba37a53e3f249ad1820ac66d9b0ccc2

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for biklimaster (3 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging biklimaster across your stack and pipelines.

  2. If you installed it — respond

    biklimaster is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If biklimaster was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks biklimaster before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. biklimaster on npm has been identified as a malicious package (versions 1.0.0, 1.1.3, 1.1.4 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

GHSA-pcfp-4v4q-w735IN-MAL-2026-017448IN-MAL-2026-017450IN-MAL-2026-017449

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks biklimaster-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

biklimaster (npm) malicious package — MAL-2026-13786 | O3 Security