Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

encrypt-string-ttaknpm

encrypt-string-ttak is a confirmed malicious npm package (MAL-2026-11011) that steals credentials and exfiltrates sensitive data (malicious versions 1.0.0, 1.0.1, 1.0.2). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in encrypt-string-ttak (npm)

MAL-2026-11011
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall encrypt-string-ttak

What this malware does

The package is published as a UniApp 'encryptString' helper but its single shipped module dist/encrypt-string.js is heavily obfuscated (obfuscator.io rotated string-array + base64 decoder + self-defending checksum loop) to hide a credential harvester. The exported handleEncryptResponse/encryptString APIs branch on URL substrings for login, register, pay, wallet, and profile endpoints, extract cleartext values including login password (p), pay password (pp), Google Authenticator secret (googleCodeSecretKey), real name (rn), KYC image URLs (u1/u2), and wallet balances (b/b1/b2/usdt) from the intercepted request/response bodies, XOR-obfuscate the payload with key 0x2537, and POST it via uni.request to a hardcoded JSONBin.io bin at api.jsonbin.io/v3/b using an author-owned X-Master-Key with X-Bin-Private:true. Records are keyed per end-user id. The obfuscation conceals both the destination host and the master API key so the exfiltration is not visible in the source. The 'encrypt-string' naming and API surface are a cover story for bulk capture of authentication factors and KYC identity data belonging to the end users of any UniApp application that integrates this module.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

3 flagged
1.0.01.0.11.0.2

Indicators of compromise (SHA-256)

bb8d4c8e562697925ed58fe79611f3adaeb70f5143c2b78ac1dce0c5e501c441
cf72c81030b9346ff3d3dd6f2e5f3395a61d433def25e5e2ea2a7e52a6051999
d0e76e07b9481e48aed15c8c742efdd04842416151389e53a82d2f7d925f0607
14d7f5ee3a1a66813ae093b96a6713382f629b5b63351c67a3f3187e5c1dafc5

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for encrypt-string-ttak (3 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging encrypt-string-ttak across your stack and pipelines.

  2. If you installed it — respond

    encrypt-string-ttak is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If encrypt-string-ttak was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks encrypt-string-ttak before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. encrypt-string-ttak on npm has been identified as a malicious package (versions 1.0.0, 1.0.1, 1.0.2 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

GHSA-mpgp-492w-x7xjIN-MAL-2026-011008IN-MAL-2026-011085IN-MAL-2026-011172

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks encrypt-string-ttak-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

encrypt-string-ttak (npm) malicious package — MAL-2026-11011 | O3 Security