Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

digitalexp-style-module-l9npm

Advisory published Updated

digitalexp-style-module-l9 is a confirmed malicious npm package (MAL-2026-14445) that opens a backdoor for remote access (malicious version 99.0.0). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in digitalexp-style-module-l9 (npm)

MAL-2026-14445
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall digitalexp-style-module-l9

What this malware does

package.json declares both preinstall and postinstall as node beacon.js, so beacon.js runs automatically on every npm install. beacon.js reads os.hostname(), os.userInfo().username, process.cwd(), and the package name, hex-encodes the collected string, splits it into <=60-char DNS labels, and issues a DNS lookup against those labels under the author-controlled domain b0.rs. It additionally issues an HTTPS GET to https://b0.rs/?poc=...&host=...&cwd=... carrying the same fields in the query string. A source comment identifies the DNS-tunnel channel as chosen for its 'best chance of escaping egress-filtered CI', confirming the dual-channel design is intentional evasion. The version number 99.0.0 is consistent with a dependency-confusion payload targeting internal-scope name resolution.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

1 flagged
99.0.0

Indicators of compromise (SHA-256)

4c1b3e9059995d4d535c65fafd0105eea420510acb17ad9befbc99c18aa25df9
9001ac45f01c90eafffa18bfc116ba35aba59f2d3b213b0b07dd82178aa5ea3c

Detection & response playbook

Backdoor / remote access
  1. Find it

    Search your lockfiles and build artifacts for digitalexp-style-module-l9 (version 99.0.0).

  2. If you installed it — respond

    digitalexp-style-module-l9 establishes remote access, so treat any host that installed it as fully compromised. Isolate the machine, remove the package, rotate all credentials it could reach, and rebuild from a trusted image rather than cleaning in place — a backdoor may have planted additional persistence.

  3. Did it already run?

    If digitalexp-style-module-l9 was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.

Frequently asked questions

No. digitalexp-style-module-l9 on npm has been identified as a malicious package (version 99.0.0 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-018684GHSA-r7fr-v3m3-mpq2

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks digitalexp-style-module-l9-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the C2 callback and severs the channel.

Explore