Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

bunnyhijack-test-0x00npm

Advisory published Updated

bunnyhijack-test-0x00 is a confirmed malicious npm package (MAL-2026-14310) that executes malicious code on install (malicious versions 1.0.0, 1.0.1). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in bunnyhijack-test-0x00 (npm)

MAL-2026-14310
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall bunnyhijack-test-0x00

What this malware does

package.json declares "bin": { "node": "./shim.js" }, which causes npm to place a node executable into node_modules/.bin. Since node_modules/.bin is prepended to PATH during npm lifecycle scripts, any sibling dependency whose install/postinstall invokes node (e.g., esbuild and similar packages with native build steps) will execute shim.js from this package instead of the real Node.js runtime. shim.js demonstrates the hijack by writing a marker file at /tmp/.bunnyhijack-test and printing a banner stating the node command was hijacked via esbuild's postinstall. The package's own description self-identifies as a self-triggering PATH-poisoning proof-of-concept, and the dependency on protoc-gen-grpc-web appears chosen to ensure a sibling lifecycle script invokes node during a normal npm install. The current shim payload is benign (marker file + console output), but the hijack primitive itself runs arbitrary code under the installer's user during install and would execute any future payload shipped in shim.js.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

2 flagged
1.0.01.0.1

Indicators of compromise (SHA-256)

9a421e1ee8b9fbe1210f431f21d68420b064cc7b685f89189ec685e579951df7
48b0f24123a037fa1032a1183e8453c9b9db3c7811a63e07124d0a0a661d4584
652b21307c316c7a3237991fdfb6dc4d43716997a91268f43fe9c9c65a3fd76e

Detection & response playbook

Malicious package
  1. Find it

    Search your lockfiles and build artifacts for bunnyhijack-test-0x00 (2 malicious versions).

  2. If you installed it — respond

    Remove bunnyhijack-test-0x00 from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If bunnyhijack-test-0x00 was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.

Frequently asked questions

No. bunnyhijack-test-0x00 on npm has been identified as a malicious package (versions 1.0.0, 1.0.1 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

GHSA-8x5v-wf85-xhj5IN-MAL-2026-018431IN-MAL-2026-018430

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks bunnyhijack-test-0x00-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

bunnyhijack-test-0x00 (npm) malicious package — MAL-2026-14310 | O3 Security