Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

commandor-corenpm

commandor-core is a confirmed malicious npm package (MAL-2026-14173) that opens a backdoor for remote access (malicious version 1.0.0). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in commandor-core (npm)

MAL-2026-14173
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall commandor-core

What this malware does

The postinstall script in [email protected] (scripts/postinstall.js) contains XOR-obfuscated byte arrays that decode at runtime (unpackSegment with key 'stf2026') to a download URL at giphub.com — a typosquat of github.com — pointing at https://giphub.com/bebraz1/PzM50V1AKG0rVlH/releases/download/null/main.exe. On Windows the script fetches main.exe into %TEMP% and spawns it detached; on WSL it decodes and invokes a PowerShell bridge command to execute the fetched binary on the Windows host. The same postinstall unconditionally POSTs a JSON body describing the host platform to a hardcoded bare-IP endpoint at http://193.70.34.101:20099/vote (assembled from a four-element array to defeat literal-IP scans) over plain HTTP. The main entry index.js is empty; the package provides no library functionality, and the sole effect of npm install commandor-core is beaconing the host and dropping and executing an attacker-controlled Windows executable.

Malicious versions

1 flagged
1.0.0

Indicators of compromise (SHA-256)

3532b684cf99d23e6ab89c60fef9f2af5b1bfe36f4d793fcaf6bcf3f718903ab

Detection & response playbook

Backdoor / remote access
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for commandor-core (version 1.0.0). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging commandor-core across your stack and pipelines.

  2. If you installed it — respond

    commandor-core establishes remote access, so treat any host that installed it as fully compromised. Isolate the machine, remove the package, rotate all credentials it could reach, and rebuild from a trusted image rather than cleaning in place — a backdoor may have planted additional persistence.

  3. Did it already run?

    If commandor-core was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks commandor-core before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. commandor-core on npm has been identified as a malicious package (version 1.0.0 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-018243

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks commandor-core-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the C2 callback and severs the channel.

Explore

commandor-core (npm) malicious package — MAL-2026-14173 | O3 Security