Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

cardano-addresses-docsnpm

Malicious code in cardano-addresses-docs (npm) Remove it immediately and rotate any exposed credentials.

MAL-2026-5802
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall cardano-addresses-docs

What this malware does

package.json declares a preinstall hook (node index.js) that runs automatically on npm install. index.js collects host identifiers (os.hostname(), os.userInfo(), homedir, DNS servers, __dirname, full package.json) and reads /etc/passwd and /etc/hosts from the installer's machine, then HTTPS-POSTs the JSON payload to swsusmhg43tobo96re8dwn0vomudi46t.oastify.com — a Burp Collaborator out-of-band domain. The package has empty author, empty description, no real functionality, and a name impersonating the legitimate cardano-addresses Cardano library — consistent with a dependency-confusion / typosquat reconnaissance payload.

Malicious versions

1 flagged
1.0.1

Indicators of compromise (SHA-256)

12312d4129dbe9579e9b2acc3761b1237f427ced1324198f61d13d349bced45a
9d99ae2a620ac8a3db31cde344d6d1e46914f785b3d5f4b8debdb20d64fa9c75

Frequently asked questions

No. cardano-addresses-docs on npm has been identified as a malicious package (version 1.0.1 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-006657IN-MAL-2026-006656

References

Credits

  • Amazon Inspector · finder

Scan your dependencies

O3 Security blocks malicious packages like this at install time and in CI.

Supply-chain protection