Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

common-tg-servicenpm

common-tg-service is a confirmed malicious npm package (MAL-2026-3288) that steals credentials and exfiltrates sensitive data (malicious versions 1.3.221, 1.3.222, 1.3.223…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in common-tg-service (npm)

MAL-2026-3288
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall common-tg-service

What this malware does

Malicious npm package published by user shetty123 as part of a Telegram account hijacking framework targeting Indian Telegram users. All 502 published versions (1.0.1 through 1.3.207) are malicious. Pairs with ams-ssk, which provides the operator's server-side AMS/CMS infrastructure.

common-tg-service performs full Telegram account takeover at runtime when the service is initialized (no install-time hooks, which lets it bypass scanners that gate on preinstall/postinstall lifecycle scripts). Behavior includes: implanting a hardcoded 2FA password (Ajtdmwajt1@) and recovery email on hijacked accounts; polling an operator-controlled Gmail inbox over IMAP (imap.gmail.com) to auto-submit 2FA confirmation codes; revoking all device authorizations except the attacker's session; harvesting OTP codes by monitoring Telegram chat 777000 and forwarding them to the operator; running SRP ownership checks against managed accounts and flagging rotated 2FA as unrecoverable; and fetching remote JSON configuration from npoint.io so operators can change behavior without re-publishing.

Blocked outbound requests are laundered through a relay at helper-thge.onrender.com. Stolen accounts and updates are exfiltrated to attacker-controlled Telegram channels (-1001801844217 and -1001972065816). Operator infrastructure includes paidgirl.site, cms.paidgirl.site, report-upi.netlify.app, and promoteClients2.glitch.me.

The package presents itself as a generic 'Common Telegram service for NestJS applications' but functions as one party's production application published as a library. Multiple installer-harming behaviors are present:

  1. Authentication backdoor. AppModule registers AuthGuard as a global APP_GUARD. dist/guards/auth.guard.js line 84 accepts the literal string 'santoor' as a valid x-api-key (or apiKey query parameter) and grants access to any route. Any NestJS service that imports AppModule from this package exposes every endpoint to anyone who sends x-api-key: santoor. The same value is baked into the shipped Swagger UI as the default auth value.

  2. Silent relay of consumer outbound HTTP. dist/utils/fetchWithTimeout.js (used package-wide) automatically POSTs the original request (URL, method, headers, body, params) to https://helper-thge.onrender.com/execute-request whenever an upstream call returns 403 or 495, unless the consumer overrides process.env.bypassURL. The relay endpoint is author-controlled and authenticated with the same 'santoor' shared secret, so the author can read every mirrored request — including any auth headers or bodies the consumer's service was sending to its own upstreams.

  3. Default proxy and IP-management routing through author infrastructure. dist/components/Telegram/utils/generateTGConfig.js line 97 defaults PROXY_API_URL to https://cms.paidgirls.site/ip-management and PROXY_API_KEY to 'santoor'. With proxying enabled, all MTProto traffic for the consumer's Telegram sessions is routed through SOCKS5 proxies chosen by the author, who can intercept, drop, or correlate the consumer's Telegram identities.

  4. Remote zip drop into the consumer's working directory. dist/cloudinary.js line 87 fetches https://cms.paidgirls.site/folders/<folderName>/files/download-all, writes the response to process.cwd()/temp.zip, and calls zip.extractAllTo(process.cwd(), true) — overwriting any files in the consumer's working directory with whatever the author's server returns. There is no hash check, signature, or version pinning, and the destination is mutable. If extracted files land where the consumer's process later loads code or config, this is full RCE in the consumer's environment.

  5. Hardcoded couplings that are not disclosed. dist/guards/auth.guard.js lines 15-26 hardcode ALLOWED_IPS and ALLOWED_ORIGINS for paidgirls.site, zomcall.netlify.app, and tgchats.netlify.app, and the package wires logging notifications to specific Telegram channels owned by the author.

Taken together, importing AppModule from this package gives the author master authentication on the consumer's API, a persistent traffic-mirroring channel, control of the consumer's Telegram proxy path, and an ability to write arbitrary files into the consumer's process CWD on demand.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

19 flagged
1.3.2211.3.2221.3.2231.3.2241.3.2251.3.2261.3.2271.3.2281.3.2291.3.2301.3.2311.3.2321.3.2331.3.2341.3.2351.3.2361.3.2371.3.2381.3.239

Indicators of compromise (SHA-256)

b90ad93b19ce09a090f9837117fe06f9a4b7b15a8268160182e9d671f0f19b65
cabb88eaa75d4e2a841ec661c545d4d4796871fc3da8e39da527bfa0a33b74a7
7cd3b6dd4751c7296aa980af903101344ab538b1a9ead17da5699ab21bcfdfdb
3e16628ad8dc1e6a6c98044a97ae5b72aec56f8a5a5bbc5bdff50bdaf51d978e
c85f345f7208547f4f43331b339412172ad80caee29352b3ea4aa5c939cdac83
cb71c95df9d76c248d6e1465348d7d089a9d76c93d47367835a9ec5c80a9b5db
ff18ab4c9d0c5460093f5754b91e97bc6a0f03fec98dc31f05468c75fefcad4b
1629ced644e954e39f32243ede3a8285eafc20d0640ef4eb683fc87f056d1d52
6b34b2ef550f0af9ef9a8a9d26f366fdf362e40323378494c895a6924d0a5d21
6e56df6810a3410e315495b78d7e102e8983650217eafaeb4f9ab926b5a8c75c
5a549fbfd512c863cdf93bc602bc01fda9bdf7b730e8cd6253ce6c24a8acb056
f714d8b7c30052980ce58752b96ce39ba7b42b6839c1ab693c3de41a698f49e9
ad2533c7e094af2e17e40ef8b7e48ca619de991111618c094340ef67a8b68dc6
6d4f3d2050ce23d25389449cc57d06e2e090679c70b82ce50179c8c2d71e991e
2967bb9b9ae0330832ed15a5b7308086467b4667496a59a5dc3aff6a03b3421e
e769b4a4ea131df52366622b66d63dfbc7c1f5642ac8478c37f86d6c25477bb8
6c8e0cda37f0b2f45f104a859fd55393122727c036d3da2bef621b00a5987015
705e7bafbb3e475d34402297e60d65c4977b4d0b093854d6cbb80d5968a30c63
83f12485ef05070641e6f0cf84b2033a6d69548eae420f07b413bea412007ede
9089f2a82d1c3a551b9d7a15f48c70f163cf1798e715a98bf19688b15d226dbd
a26f18f79eac39fa511ea423e7ba11f400bddc3b576627119a256ca0af213221

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for common-tg-service (19 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging common-tg-service across your stack and pipelines.

  2. If you installed it — respond

    common-tg-service is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If common-tg-service was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks common-tg-service before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. common-tg-service on npm has been identified as a malicious package (versions 1.3.221, 1.3.222, 1.3.223, 1.3.224, 1.3.225, 1.3.226, 1.3.227, 1.3.228, and 11 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-006138IN-MAL-2026-006685GHSA-wvhv-cgwm-v2hvIN-MAL-2026-008479IN-MAL-2026-008365IN-MAL-2026-008477IN-MAL-2026-008478IN-MAL-2026-008366IN-MAL-2026-008476IN-MAL-2026-008589IN-MAL-2026-008591IN-MAL-2026-008961IN-MAL-2026-009006IN-MAL-2026-009352IN-MAL-2026-009356IN-MAL-2026-009556IN-MAL-2026-009561IN-MAL-2026-009551IN-MAL-2026-009566IN-MAL-2026-009557

References

Credits

  • Amazon Inspector · finder
  • SafeDep · finder

Detect & block this

O3 blocks common-tg-service-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

common-tg-service (npm) malicious package — MAL-2026-3288 | O3 Security