Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

cms_compnpm

Malicious code in cms_comp (npm) Remove it immediately and rotate any exposed credentials.

MAL-2025-192555
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall cms_comp

What this malware does

The package cms_comp was found to contain malicious code.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

3 flagged
999.0.0999.0.1999.0.9

Indicators of compromise (SHA-256)

e58e38c37e8492486fd771954f0b1906c083a4dd5741600ca28a0bed5dd919a7
7762e8867157bd05bfa8858e8f90ecd85ed0d6cf08c2435d264b9c61ad3420de
6addf1f4790fff1eaea2d292641b5759df9e7e6f4dc555e35d5f3abea11e565e
3371a724eb9a9454d6d13614ef6e8b42ac9046aa34d74ce09f7eb305a00aa231

Detection & response playbook

Malicious package
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for cms_comp (3 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging cms_comp across your stack and pipelines.

  2. If you installed it — respond

    Remove cms_comp from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If cms_comp was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks cms_comp before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. cms_comp on npm has been identified as a malicious package (versions 999.0.0, 999.0.1, 999.0.9 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

GHSA-7766-4vwr-vg78RLMA-2025-06097RLUA-2026-01209

References

Credits

  • Amazon Inspector · finder
  • ReversingLabs · finder

Detect & block this

O3 blocks cms_comp-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

cms_comp (npm) malicious package — MAL-2025-192555 | O3 Security