Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

frenchworldcupwinnpm

Advisory published Updated

frenchworldcupwin is a confirmed malicious npm package (MAL-2026-14318) that executes malicious code on install (malicious versions 1.0.0, 1.0.1, 2.0.0…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in frenchworldcupwin (npm)

MAL-2026-14318
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall frenchworldcupwin

What this malware does

package.json declares its sole runtime dependency client-marker-packet-cluster as an arbitrary HTTPS tarball URL on a non-registry host (artifacts.stg.yosiroute.com), and index.js unconditionally re-exports that dependency via module.exports = require('client-marker-packet-cluster'). Installing this package causes npm to fetch and load code from that host into the installer's dependency graph with no version pin, no integrity hash, and no publisher relationship to the declared repository. Whoever controls artifacts.stg.yosiroute.com controls the code that executes when a consumer of this package require()s it. Package metadata is placeholder-shape (author Package Registry, description Generated package, repository pointing to a non-existent github.com/example/... org), so no legitimate publisher context anchors the external code source.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

4 flagged
1.0.01.0.12.0.02.0.5

Indicators of compromise (SHA-256)

5cc5e745852cc2c791421f3bf384a281040b1cf8e01f8e74782b2a48fe0390b8
f28b41919d402aff87ec13d36b2419e4c19dcc209dcb6ffa3e736de5be2803e6
7b01a7372d2bf2f647fa9730af4fd11ec76bdf9535fc88530add00f12e6c2319
f6bde6bfbd2012c8dd37b2af8dfb0e12a86cadf603290ce2e98b6a88ef97a827
69dc5413f2b8cac60c8648d7698317fc495cd3added122eec8beb37e45ebccb7

Detection & response playbook

Malicious package
  1. Find it

    Search your lockfiles and build artifacts for frenchworldcupwin (4 malicious versions).

  2. If you installed it — respond

    Remove frenchworldcupwin from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If frenchworldcupwin was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.

Frequently asked questions

No. frenchworldcupwin on npm has been identified as a malicious package (versions 1.0.0, 1.0.1, 2.0.0, 2.0.5 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

GHSA-hp4f-wg89-v3fgIN-MAL-2026-018455IN-MAL-2026-018488IN-MAL-2026-018462IN-MAL-2026-018479

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks frenchworldcupwin-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

frenchworldcupwin (npm) malicious package — MAL-2026-14318 | O3 Security