Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

create-backend-scaffoldnpm

create-backend-scaffold is a confirmed malicious npm package (MAL-2026-11270) that steals credentials and exfiltrates sensitive data (malicious versions 1.0.0, 1.0.1, 1.0.2…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in create-backend-scaffold (npm)

MAL-2026-11270
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall create-backend-scaffold

What this malware does

playground/src/routes/auth.routes.js contains an obfuscated trailer appended after the normal router export. The trailer aliases require/module to globals, then uses a custom seeded-PRNG string-shuffle routine (JFG) to deterministically reconstruct the identifier 'constructor' from a scrambled alphabet, obtains the Function constructor by that indirection, decodes a hidden string payload, and invokes it as JavaScript at module load. The file is imported by src/app.js, which is loaded by the package's shipped server.js, so running the shipped server (e.g. node server.js or npm run dev) executes the hidden payload. The obfuscation technique (arithmetic-PRNG string permutation to hide 'constructor' and the Function body) is designed to evade static keyword matching. The tarball additionally ships a.env file containing a live MongoDB Atlas connection URI for the author's own cluster (author-owned credential leak, separate from the payload behavior).

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

9 flagged
1.0.01.0.11.0.21.0.31.0.41.0.51.1.01.1.11.1.2

Indicators of compromise (SHA-256)

f749e8b76ccc1619cfe98769cfcc133208c515f14ed198115a55587b28a49951
0201b01c3bd9dbea597956acb10299aa22cd7976dcb7863348892f46512b47f1
4d324a5eb7003c62fdf99ad4f150d9ba969eb9c7a3d7cf7b38d2975805f7c30a
255f889733670ee1a56c6fc7904bf5be432a8d97248679977c9cd1ab6ff9c0f1
e78db15e0cc4a113282efcca73548f50bb61432d673086b03b93da4246dbebf3
64f68ffbe38ed06f4c7f3c8f1e59e849bead33d44f451b95d61ddb5595153d26
83f2cb345437a6122d517fc3bd868bb6d1352ac1e3ff3a272dfb888e5f7db679
988cc3d266a567e721e8a4b6aa34a4c1e814df0f371566b82bcadefea761f7fa
a97e3c2ba5a1faeea48f5f3dbfa05ed1fcce112cda9dfe64c681bac9248d6b09
b875d230fd5f70b689baaf66a501d2d294b3e02ff3524c02a8ec24b4eb2a2dbb

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for create-backend-scaffold (9 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging create-backend-scaffold across your stack and pipelines.

  2. If you installed it — respond

    create-backend-scaffold is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If create-backend-scaffold was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks create-backend-scaffold before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. create-backend-scaffold on npm has been identified as a malicious package (versions 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.1.0, 1.1.1, and 1 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

GHSA-p8mm-7vhx-3cr2IN-MAL-2026-011228IN-MAL-2026-011222IN-MAL-2026-013195IN-MAL-2026-013144IN-MAL-2026-013362IN-MAL-2026-013344IN-MAL-2026-013376IN-MAL-2026-013378IN-MAL-2026-013346

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks create-backend-scaffold-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

create-backend-scaffold (npm) malicious package — MAL-2026-11270 | O3 Security