Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

editable-contractsnpm

editable-contracts is a confirmed malicious npm package (MAL-2026-11967) that steals credentials and exfiltrates sensitive data (malicious versions 0.0.12, 0.0.13, 0.0.14…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in editable-contracts (npm)

MAL-2026-11967
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall editable-contracts

What this malware does

npm/editable-contracts is affected by the large-scale, self-propagating npm supply-chain worm of 2026-08-04 (the "Shai-Hulud: Here We Go Again" wave) — the same campaign that began with the compromise of the keyv and cacheable maintainer account. The listed version(s) were trojanized and republished by the worm after it reached an npm publish token belonging to a maintainer in this namespace; the payload enumerates every package a stolen token controls and republishes each with the same hook, so many packages under this scope were poisoned in the same short window. Every poisoned release adds a preinstall hook ("preinstall": "node setup.mjs") that runs on a bare npm install, before any project code. setup.mjs downloads a standalone Bun runtime and runs a byte-identical, heavily obfuscated ~728 KB second-stage credential stealer (shipped as Math_Symbol.js / math_init.js). It harvests GitHub, npm, AWS, GCP, Azure, HashiCorp Vault and Kubernetes credentials plus generic secrets and private keys (TruffleHog-style sweep), reads CI/CD secrets and identifies build runners, then republishes further packages the stolen token can reach. Rather than a fixed command-and-control host, it exfiltrates stolen findings to attacker-created GitHub repositories (descriptions reading "Shai-Hulud: Here We Go Again") and over DNS. Treat any environment that installed an affected version (with install scripts enabled) as compromised: rotate and revoke all reachable credentials (npm and GitHub tokens, cloud keys, Vault/Kubernetes secrets, and CI org/repo secrets). Part of the August 2026 npm worm that poisoned 400+ packages across many organizations.

Version 0.0.24 of editable-contracts (a mobx-based JSON editable-contracts helper published under the ServiceTitan namespace) adds install-time execution machinery not present in prior releases and not reflected in the README, src/, or dist/ tree. package.json declares scripts.preinstall = "node setup.mjs". setup.mjs uses hex-identifier and proxy-object string obfuscation to hide its constants, then downloads a Bun runtime archive from https://github.com/oven-sh/bun/releases/download/bun-v<version>/<archive>.zip, extracts it to a temp directory, chmods the binary executable, and invokes it against a sibling file math_init.js via execFileSync. math_init.js is a single-line ~727KB string-array + rotation obfuscated bundle (marked // @bun @bun-cjs) with rotation function WV8StW and index array n7gIxM — classic javascript-obfuscator scaffolding hiding the payload's actual behavior. The obfuscated payload is unrelated to the advertised JSON-form library and is executed automatically on npm install by every downstream consumer. The pattern — grafting a preinstall dropper, an alternate-runtime fetch, and an obfuscated payload onto an otherwise legitimate library published under a trusted namespace — matches a hijacked-publish supply-chain compromise.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

16 flagged
0.0.120.0.130.0.140.0.150.0.160.0.170.0.180.0.190.0.200.0.210.0.220.0.230.0.240.0.250.0.260.0.27

Indicators of compromise (SHA-256)

6e2e6036d5e16b62eda6834ad87d8a5358e902fd6bad17732a0c657fc17b7e21
0c39c1d5221211f2288b905fd232144c3a21f68209fd93019f565e174f5b3ea2
225c240afede52fafcae62e1faa8f8d679e03702c0335bf30382fe955d41a78b
474f1d3b37ea8c56a1fa1ceb784ff09454859ef02ca23dd0071fdd9e86545698
48ccfdb7567b9f77ed886aee36e08cc7a437e13fc3754f81a143f8c00115e8c0
8153213161cfde4cc363675d1ec329a1fc2066fbc34dc64bc73484d37af0d00a
d90f77f7576ef149800b4f56b1931d2e3701023eb5ceea86535e0765d7855e5a
eecbf4447170cb6572aef8c49dec7815210740369d4934918d3aa68b67b9254d
246ff4773dc5dd335914c42c2c0d3f999f94204b2ad53cac8569eeb57ccb1bcd
613b38ee8ec22b1be0f97e2b55f39bc14e96f08459a2aa1b8df2158687a03f6e
7497b8a2b483d44340749dd54482c9c194520d1c983fc0a312c1154d1f21efa1
7ea9e6999cdc8a8beb04f9a21051c22f539010362851aa7ced48bcb53c6ce08b

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for editable-contracts (16 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging editable-contracts across your stack and pipelines.

  2. If you installed it — respond

    editable-contracts is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If editable-contracts was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks editable-contracts before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. editable-contracts on npm has been identified as a malicious package (versions 0.0.12, 0.0.13, 0.0.14, 0.0.15, 0.0.16, 0.0.17, 0.0.18, 0.0.19, and 8 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

GHSA-wxxq-25jf-6998IN-MAL-2026-013656IN-MAL-2026-013674IN-MAL-2026-013678IN-MAL-2026-013650IN-MAL-2026-013730IN-MAL-2026-013702IN-MAL-2026-013501IN-MAL-2026-013462IN-MAL-2026-013731IN-MAL-2026-013534IN-MAL-2026-013559

References

Credits

  • Aikido Security · finder
  • Amazon Inspector · finder
  • SafeDep · finder
  • Socket Threat Research Team · finder

Detect & block this

O3 blocks editable-contracts-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

editable-contracts (npm) malicious package — MAL-2026-11967 | O3 Security