Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

coral-wraithnpm

coral-wraith is a confirmed malicious npm package (MAL-2026-5682) that steals credentials and exfiltrates sensitive data (malicious versions 1.0.0, 1.0.1, 1.0.2…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in coral-wraith (npm)

MAL-2026-5682
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall coral-wraith

What this malware does

The package's postinstall.js runs at install time and performs a credential-harvest + host-tampering chain against the installer. It enumerates npm credentials by calling npm config get for keys including _authToken, _auth, registry, //registry.spectral-corsair.htb:1337/:_authToken, //registry.spectral-corsair.htb/:_authToken, and //154.57.164.64:32271/:_authToken, dumps the full npm config list --json, and reads /usr/lib/node_modules/npm/.npmrc, /etc/hosts, /app/.bowerrc, /root/.bowerrc, and source files under /app (Cargo.toml, main.rs) plus filesystem-wide flag/secret greps. The collected output is base64-encoded and HTTP PUT to a hardcoded bare IP http://154.57.164.64:32271/api/modules/.... Separately, postinstall.js appends 154.57.164.64 registry.spectral-corsair.htb to /etc/hosts when not already present, then queries the spoofed registry via curl and npm view — install-time host-file tampering that redirects a registry hostname to an attacker-controlled IP and enables later package substitution / MITM. Execution is gated by an anti-analysis shouldRun() that bypasses CI environments (GITHUB_ACTIONS, RUNNER_OS, CI), Chinese registry mirrors (npmmirror, tencent, cnpm, taobao), and /tmp working dirs, and only fires when the hostname matches a 12-hex Docker short-id pattern and cwd contains /app — narrow targeting that confirms intent while shipping the malicious code unconditionally.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

The OpenSSF Package Analysis project identified 'coral-wraith' @ 6.0.0 (npm) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.

Malicious versions

47 flagged
1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.81.0.91.0.101.0.111.0.121.0.131.0.142.0.02.0.12.0.22.0.32.0.43.0.04.0.05.0.15.0.25.0.36.0.07.0.07.0.17.0.27.0.38.0.09.0.010.0.011.0.012.0.012.0.113.0.014.0.015.0.016.0.017.0.018.0.019.0.019.0.120.0.021.0.022.0.0

Indicators of compromise (SHA-256)

f10fa9dc8c51419efaef960da0e4bed5e80346be9279a40d610d695a8571f6b7
38185d2c242e73e720a6be3f2b234a23119ec986c4b7ca57ca789e24616c1029
07ca8ef5365aa5a79c231f971e0c50354b3c5d62317b19a17386299f7f882141
1e3ee9477a007d9fe71d2addab0b98096b39bc1f70678f46463c6ff646686643
966aea4e5108e3e6bf1c8aa023b6c2c1af3d3531b02e767d29fd44125b20dd47
c0406441b0527808071af164346dde86418d0d8565130e2aa55abba2d43e1a5c
c0b02d69949d2eb0159c94a4b28d593c20124a6a5e5ab25834ba212ac7b24723
ffe3e4fd2294a8ec20e46a279ae25d60e304bcf4612c8218f8ab73c2eba03aeb
62937ec57ea3022c147f548e12d55d09e6756954c57a33dde68a38248f8b9a16
9c73d8e1c9490a5fa2b0db0d45edf27050d790987304fce423d77224abd38b00
9d339a19ddd723fc7516eb40b4fb2f3f58398c498b7f735b698acabc1ea4b0e7
01b204f6af0bec029b969a5075a0a9b9d188c1bd97275ab12c671d075b78f3c7
08d9fea73abaf82bf48558a359aea60b908110237c46391758f128db797a94d8
801116f949670637567f431f0681098c17f5c5d28148b472987971c3152e2874
8ffda67261338bad046d372de07f758310f8c38ed322b72c5c78ebe3284a38f0
92d52d897e643ef05e5aef82ee8727d442c4f3223f6bca1716a04573776022f1
b66d2c0bffaebf7e1fdb09f9dd217a729285bda9a07ec1a237a299bf7dd34a73
1752c7b1561562308ae29c0c4a5950c1d3b8a497145009642a4f197091614ae9
29ffb16180dbb8c3449b9c65c3cd318f99b0a4fcc7c0fdce38f75a129a1a033e
62adb02caa502cf1311c96d5e5a129da23cd93d238a361b8a03c58eebb69ce1a
86310c9cb72f594270d4d8aee2052a820d6d8c9be286326b3055022acb9447d6
86386b6c950f45a1098c26a6b5dbffe1b8539fdefceb68d8ad71b3f219c2984d
9b6f290eb33a3c8d26147a177095a365fdb65a53b6881d89ac5714c97b1edc92
a1e0b1e77eacd162a3457efdd4a5d80f0c4b2db70b32f419b28d768241072398
c0753af6eda21e2ba2a5b2676f438107d3777ee94dfafc2db79bd2c8b0ff7de5
27fdc179715e175ddc69c07f81f52ad82a03acc7734f9d0ae963b48a5c4563b6
4c82e9295508c7f78fef421517fcd789c93436075f7839838a4422d9d0a414ce
5cc6c0820e0aa5ee121db6efd622d15fa2611f39ab6ddaedb0b93931c8759fac
95c0368c058aa9affd6ababcd01a5d46413f6438e412b86240e692d69e3e5560
bdfdc1d81747834ae7003133371ab0802afea9a2ed910edefd30f5f588673511
cb355c208adb8c56680c10e7bace00d74a7762a872e2845bf5a9e2a886bf70e0
cf0e5e4aa66ffeb1481fd587c96f596a227c9388b86b3a3443749b5ec9eb09f1
eba05de91fe8c514f45bea8cd9a532f34527f6d83cfaa672b7f91316938c838f
49382cc3a8b2920c7cd40c64d29e5b0e32f51aaad7db70c39d091ea27dde5109
877d0b22b57cd9428ed7c2b4b22aaed8c903f1a4f6b3b2adeb83a083f64514f9
c0bfbc6f714238d316e71be85598cca2980f243e5720688006ea5e678506f9cc
e1df06d3c1724e8f6a1ab563b6e8adc264cfeac7eb1a29326f5d3c301b2e1e91
eb60a6403da3a982af7df33f56db65e8aeee56086db82cbf20cb9de78a91a820
5e6d0f852fcbecaea298392cbfa22b10a2158c45d83b88abb2fc1cf47aef56e0
9257dc89167fcd66b84ef3ad009774f4ddf97b0eafc33095f898b833a050d00c
c4be37bb7001c7a0c56c2dcdaace7cb99d2145b9e4fdd21d9829c5884aac3b03
e86206fda8399d3203f02cad106438dc877e54ed89d2c02d8e4f8a357d8ec489
1cce74643d3d96bb21b153accc300d89e0cb9d8c4f1922798bd73dadacac617f
1da8731e34f645992420af777397456858a3acd8ab198e14034f294fcf255f25
3d3050f6ec6e82aa07890b59efff51e255141e1d65e2f6a33d49a77dd1ab31e2
c6def8d269b89fd7023f1720990813c17bcbc37be1cf50ad2a48bd5c6e901257
ce09dc236450733d125aa418464a1e6d4f0ca97e4fa6d8be6e8d1482867fa070
7e5c1ef9e229fba9a090ab62cddb6c3a73f53995ed34b5a1b7ba08c2f5db84a3
cfc9bc123480eff39635ee498f9b7f2319b734f3fd3c02438e1fba5110082969

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for coral-wraith (47 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging coral-wraith across your stack and pipelines.

  2. If you installed it — respond

    coral-wraith is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If coral-wraith was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks coral-wraith before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. coral-wraith on npm has been identified as a malicious package (versions 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, and 39 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

GHSA-f2r7-23p9-8jffIN-MAL-2026-005945IN-MAL-2026-005960IN-MAL-2026-005937IN-MAL-2026-005930IN-MAL-2026-005935IN-MAL-2026-005931IN-MAL-2026-005961IN-MAL-2026-005958IN-MAL-2026-005942IN-MAL-2026-005928IN-MAL-2026-005955IN-MAL-2026-005934IN-MAL-2026-005921IN-MAL-2026-005933IN-MAL-2026-005932IN-MAL-2026-005941IN-MAL-2026-005925IN-MAL-2026-005927IN-MAL-2026-005965IN-MAL-2026-005939IN-MAL-2026-005940IN-MAL-2026-005957IN-MAL-2026-005924IN-MAL-2026-005938IN-MAL-2026-005947IN-MAL-2026-005950IN-MAL-2026-005962IN-MAL-2026-005948IN-MAL-2026-005956IN-MAL-2026-005944IN-MAL-2026-005949IN-MAL-2026-005923IN-MAL-2026-005953IN-MAL-2026-005952IN-MAL-2026-005936IN-MAL-2026-005951IN-MAL-2026-005929IN-MAL-2026-005964IN-MAL-2026-005922IN-MAL-2026-005954IN-MAL-2026-005959IN-MAL-2026-005943IN-MAL-2026-005946IN-MAL-2026-005963IN-MAL-2026-005926IN-MAL-2026-009011IN-MAL-2026-009511

References

Credits

  • Amazon Inspector · finder
  • OpenSSF: Package Analysis · finder

Detect & block this

O3 blocks coral-wraith-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore