Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

fhirproxy-utilsnpm

Malicious code in fhirproxy-utils (npm) Remove it immediately and rotate any exposed credentials.

MAL-2026-5461
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall fhirproxy-utils

What this malware does

On npm install (via the prepare lifecycle hook and many other lifecycle aliases) and on require(), index.js performs broad reconnaissance and exfiltration of the installer's environment. It collects hostname, username, architecture, working-directory tree, network interfaces, /etc/resolv.conf, process list,.git/HEAD, UID/GID, project package.json metadata, ~/.npmrc registry/scope configuration, the developer's git identity (via git config --global user.email), CI/CD environment variables (GITHUB_, GITLAB_, AWS_, CIRCLE_, etc.), and the presence of ~/.ssh, ~/.aws, ~/.kube. When running on a cloud instance it queries the IMDS endpoint at 169.254.169.254 (stored as the decimal-encoded host 2852039166), obtains an IMDSv2 token, fetches the IAM role and temporary STS credentials, and includes the first 40 characters of the access token in the payload; equivalent paths exist for Azure and GCP metadata. It also performs DNS reconnaissance against internal-only hostnames (kubernetes.default.svc.cluster.local, vault.internal, consul.service.consul, gitlab.local, jenkins.local, redis.internal, etc.) to map the victim's internal network. Collected data is base64-encoded, fragmented, and exfiltrated via chunked HTTPS GET requests to momo-rest.lapxa354.workers.dev (a Cloudflare Workers C2 endpoint), with the destination obscured via Buffer.from("bW9tby1yZXN0LmxhcHhhMzU0LndvcmtlcnMuZGV2", "base64").toString() at index.js:43. The package additionally squats common build-tool command names by declaring bin entries for webpack, vite, tsc/tsnode, jest, eslint, gulp, next, turbo, and prettier — all aliased to index.js — and spawns the real local tool (e.g. webpack-cli) afterwards to mask the malicious behavior when invoked via PATH or npx.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

1 flagged
1.0.8

Indicators of compromise (SHA-256)

405cf847121f4bfed32bc5679a40b64c1338b142af75823ef9583944a7ae7b5a
4bebd4a133fd4719ba9fec03a4bcdd3ae5090aa2054beca2e84fa7335dd5c9b7

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for fhirproxy-utils (version 1.0.8). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging fhirproxy-utils across your stack and pipelines.

  2. If you installed it — respond

    fhirproxy-utils is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If fhirproxy-utils was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks fhirproxy-utils before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. fhirproxy-utils on npm has been identified as a malicious package (version 1.0.8 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-005167GHSA-cw9q-6cmp-p38r

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks fhirproxy-utils-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

fhirproxy-utils (npm) malicious package — MAL-2026-5461 | O3 Security