Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

cache-section-helpernpm

Malicious code in cache-section-helper (npm) Remove it immediately and rotate any exposed credentials.

MAL-2026-5604
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall cache-section-helper

What this malware does

package.json declares a postinstall hook (node -e "require('./loader.js')") that runs automatically on every npm install. loader.js hex-decodes the string 68747470733a2f2f6a736f6e6b65657065722e636f6d2f622f4c34333541 to the URL https://jsonkeeper.com/b/L435A, fetches a JSON document from that anonymous paste host, extracts a manifest.session field, writes it to a temporary file under os.tmpdir()/wpc-*/cfg-<ts>.js, require()s it to execute the attacker-supplied JavaScript, then deletes the file to hide traces. The dropper is launched via spawn(process.execPath, [tmpFile], { detached: true, stdio: 'ignore', cwd: os.tmpdir() }).unref() so the child Node process outlives the npm install and runs without producing visible output. The package presents itself as a webpack caching helper (class WebpackCachePlugin in index.js, a README that instructs npm install cache-helper — a different name suggesting impersonation), but the advertised plugin code is trivial; the real behavior is the install-time dropper. Every installer fetches and executes attacker-controlled, mutable, unauthenticated code from a paste host with no integrity verification.

Malicious versions

1 flagged
1.0.7

Indicators of compromise (SHA-256)

4da4f8014e1d74a0329e5f414692fb9267f2eab553d393e47d810078f1708b06
cad3d2732831e4b798073aff289abd1abdbb718b4caa9e4f970a0dd3f7733653

Frequently asked questions

No. cache-section-helper on npm has been identified as a malicious package (version 1.0.7 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-005702IN-MAL-2026-005701

References

Credits

  • Amazon Inspector · finder

Scan your dependencies

O3 Security blocks malicious packages like this at install time and in CI.

Supply-chain protection
cache-section-helper (npm) malicious package — MAL-2026-5604 | O3 Security