Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

electron-internal-utilsnpm

Malicious code in electron-internal-utils (npm) Remove it immediately and rotate any exposed credentials.

MAL-2026-6186
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall electron-internal-utils

What this malware does

On npm install, package.json's postinstall script executes curl http://9ph8dp.ceye.io, an out-of-band DNS/HTTP interaction service controlled by the package author. The callback signals the attacker that the package was installed on the host and leaks the installer's public IP and DNS resolver metadata. The package ships no functionality (index.js contains only module.exports = {};) and its name impersonates the Electron project's internal-utilities namespace, consistent with a dependency-confusion attack against projects that reference internal Electron helpers. Any environment that runs npm install on this package will silently beacon to attacker-controlled infrastructure.

Malicious versions

1 flagged
1.0.0

Indicators of compromise (SHA-256)

e07ff16a8f4a44a8ccfc2f6f2a91eee6dbd3d1de9f1c4d6ca95e0e48999202ef

Frequently asked questions

No. electron-internal-utils on npm has been identified as a malicious package (version 1.0.0 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-007049

References

Credits

  • Amazon Inspector · finder

Scan your dependencies

O3 Security blocks malicious packages like this at install time and in CI.

Supply-chain protection
electron-internal-utils (npm) malicious package — MAL-2026-6186 | O3 Security