Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

electron-orbitnpm

electron-orbit is a confirmed malicious npm package (MAL-2026-6723) that steals credentials and exfiltrates sensitive data (malicious versions 1.0.3, 1.0.4, 1.0.5…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in electron-orbit (npm)

MAL-2026-6723
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall electron-orbit

What this malware does

On require('electron-orbit'), the module unconditionally fires an auto-prefetch pipeline in Node contexts (when no document is present) that opens a raw node:net socket to electronorbit.blob.core.windows.net:443 and speaks a hand-written TLS 1.3 stack (custom ClientHello, HKDF key schedule, AES-128-GCM in aetherls.ts) rather than using https, bypassing standard TLS interception and static inspection. Every network-related string — the Azure hostname components, node:net, connect, ALPN http/1.1, HTTP request line, marker filename, and process.env enumeration keys — is XOR-obfuscated through a helper __s(key, arr). The postinstall script install.js writes an install marker to os.tmpdir()/electron_orbit_install_marker.txt containing process.env entries whose keys match path (PATH-family variables) plus process.cwd(), and separately stages os.hostname(), os.userInfo().username, process.version, platform and arch into a decoy file under bin/formatters/ prefixed with a fake native-binary magic byte. On require, index.ts reads the tmpdir marker, XORs it with the string electron-orbit, hex-encodes it, and appends the result as a query-string suffix to the Azure blob URL, so the storage account's HTTP request logs capture the installer's PATH-family environment and working directory. Activation is gated: the destination host is only populated when the SHA-256 of process.env.BuildType is a substring of a hardcoded 64-hex constant (0ceaa396…8295); otherwise the source is set to %TEMP% and the request fails to resolve, keeping the payload dormant on non-targeted installers and firing only when a specific env var is set (e.g., in a chosen CI environment). The advertised purpose (Electron-style runtime discovery) has no relationship to icon fetching or SVG rendering; the icon surface is a pretext — getRegisteredIcon returns a hardcoded empty <svg> regardless of the network response.

Malicious versions

32 flagged
1.0.31.0.41.0.51.0.61.0.71.0.81.0.91.0.101.0.111.0.121.0.131.0.141.0.151.0.161.0.181.0.201.0.211.0.221.0.231.0.241.0.251.0.261.0.271.0.281.0.291.0.301.0.311.0.321.0.331.0.341.0.361.0.37

Indicators of compromise (SHA-256)

10848278600fe8696063359d8f022d4d0732ac5825506d800707afe08110320e
b925cd8754d91ca746f88287af2d6331578be16f842665ba2dd746665d20089a
47e8d77c0b581ef00c04e40584b9242f1e948d0330e76f877783a975d863d244
92153bc4e68cffd4c1d0e5b11ca3bc772f77b25cfbe012b5f71614de1288b990
952200b7df4332004cc5fefbaa4bcb7d8f1ab097c295e79afae66fe19d23aae6
e88ccedca508e4a1138bf6749aeb112e97fdea672ffd4d8553d99da05dbc84a5
8de289d6073561060a409931399a18484fd826ada63e5fae4f2b30c618172ac4
c29ff208e55231dcf792181b153ecbf8d546a0f285f415ccae0358f0d0e757d1
816096531ac2b919acfef3d9512968cf694c98e14cb2ee1ce1430877ce39170a
19c68f98c57515e576aef9cc6bd4d2801f813b382d3ea55091c423663d8106cf
36ceb992564dfb37d1d5d28dc2b31f99361fc1392c85592bfce2b97eef195c90
54c50d1b1671037faea6193cf6d7994bfd7c4fba7640d2935546712d7ebed8e7
77275717c30e5629daba99b0a9ae1dd5a30b7b3fb013fe66a66a8213ab32ad8e
78d034e73e1a01e3c47c1b0ade337cd56fd392e0be1398b13fbdf051d6166220
bae81fe7c1395441c366ea9e03e33844d0f8ce1cd5d05c40873cd4fb858bb64d
6245487ae50f09a690451f235b8c9855d2f666f2b0a25e93871cf7a1251b5d69
7faf51a6c9d6ed9fce8cf9de9ea8afee0e9c3dc1fb254e8cd0c3c2a8ca61323f
74a4c2467a3c20b1532b6935cc3ae3c984c06c696a4a430c886f155a562ce3f4
8607b322e5ebd914296b192b0877ba45f5e9750dc69c924f7d939d2b8b378c5f
8c298b3f9b2691ab1ebb958398e1736aa636d9ee4e5d54acb0b57a5e1f93167c
9c9d089e560d6af7ee6fbfc04edfc6f073ef8fec7f555102011e47f2f33a3df7
d9634442d2460040970659611fb37887044b6a6f10a63c17f73161b1b21a3ce0
150616fc5c43dab7fcc26b65b7817ccc01229778cc7bcf143025d16b4d3cc3da
1d12525ca427cbe9367a0caefb4b1020cc0593fa2b428b691c0e635a48d2757c
70733642ade646f823a77e8ae1616337f76e9340fc84a3a5da7c2365a58f6d00
c37583c0ed58e2b399630b0a314361d54f7b4927faeadcba99122205c37d78fa
1402a4a73f05f68a55951e93a03c1758d6406fb97a056d84802c21244e3d5393
b81cc5f0d2ed6deaed9b0956f47d024f9c42b291090c71d5abec8e34d0c2ab62
c3b84ec0bc193e98c0c57657693f84fc2ccbe0ef8ed7a66b919d9ec486d5e515
b84bfc662b2e38c56da1343ec68aa18255a7a43be7a97ef9227de541e0a9a5a2
c7750cd6d1bd46851da24a4090675984c9f66dd4b8d3634e9a58ce6896a2c11c
4fb75f276b6b13ba249c3cc7c393f14c5c93c49b643f8ac5a4c10de3bdfbf25c

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for electron-orbit (32 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging electron-orbit across your stack and pipelines.

  2. If you installed it — respond

    electron-orbit is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If electron-orbit was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks electron-orbit before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. electron-orbit on npm has been identified as a malicious package (versions 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.0.10, and 24 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-007924IN-MAL-2026-007932IN-MAL-2026-007931IN-MAL-2026-007936IN-MAL-2026-007922IN-MAL-2026-007923IN-MAL-2026-007929IN-MAL-2026-007926IN-MAL-2026-007918IN-MAL-2026-007933IN-MAL-2026-007928IN-MAL-2026-007930IN-MAL-2026-007939IN-MAL-2026-007914IN-MAL-2026-007911IN-MAL-2026-007912IN-MAL-2026-007919IN-MAL-2026-007917IN-MAL-2026-007916IN-MAL-2026-007915IN-MAL-2026-007920IN-MAL-2026-007937IN-MAL-2026-007927IN-MAL-2026-007938IN-MAL-2026-007934IN-MAL-2026-007935IN-MAL-2026-007941IN-MAL-2026-007921IN-MAL-2026-007913IN-MAL-2026-007925IN-MAL-2026-007910IN-MAL-2026-010334

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks electron-orbit-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

electron-orbit (npm) malicious package — MAL-2026-6723 | O3 Security