Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

exodus-solana-sdknpm

Malicious code in exodus-solana-sdk (npm) Remove it immediately and rotate any exposed credentials.

MAL-2026-5442
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall exodus-solana-sdk

What this malware does

Package name impersonates the Exodus cryptocurrency wallet brand (exodus-solana-sdk). package.json declares a postinstall hook (node src/canary.js) that fires automatically on npm install. canary.js performs a DNS lookup and HTTPS GET to a hardcoded 96e03fa6c292469a-172-245-86-254.serveousercontent.com endpoint — a serveo.net reverse-tunnel domain that is anonymous, mutable, and operator-controlled. The hostname embeds an IPv4 address (172.245.86.254), and the response body is silently discarded (r.resume()), confirming the request's purpose is reconnaissance rather than data delivery to the installer. The beacon reveals the installer's egress IP, DNS resolver, and install-time event to whoever controls the tunnel. The package's own description self-identifies as a 'Security research canary — Exodus HackerOne PoC. Not a real package.', but it is published to the public npm registry where any developer who mistypes the package name will execute the beacon. Self-declared research framing does not neutralize installer-side harm: install-time outbound network to an anonymous tunnel under a brand-impersonating package name is the typosquat-reconnaissance attack shape.

Malicious versions

1 flagged
99.0.0-canary.1

Indicators of compromise (SHA-256)

8f222f4981a374a98219a8b4fd00b46127e599c448f2f0881e558f4984c57d08
ecffe98bff5e1c4655631cf8f92b1b1ccb534e0eeaa7043fab0d5fa1fbfabc35

Frequently asked questions

No. exodus-solana-sdk on npm has been identified as a malicious package (version 99.0.0-canary.1 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-005110IN-MAL-2026-005109

References

Credits

  • Amazon Inspector · finder

Scan your dependencies

O3 Security blocks malicious packages like this at install time and in CI.

Supply-chain protection
exodus-solana-sdk (npm) malicious package — MAL-2026-5442 | O3 Security