Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

gethandler-apinpm

Malicious code in gethandler-api (npm) Remove it immediately and rotate any exposed credentials.

MAL-2026-5473
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall gethandler-api

What this malware does

On npm install, postinstall.js unconditionally sends an HTTPS GET to https://webhook.site/18dc4281-d366-438a-9186-76fbcd56ade5 carrying the installer's hostname (os.hostname()), username (os.userInfo().username), platform (os.platform()), current working directory, package name/version, CI environment indicators, and a timestamp. Errors are silently swallowed so the install never visibly fails. The package.json self-describes as a 'defensive typo-squat' placeholder for the @getd/* namespace, but regardless of stated intent the behavior is non-consensual install-time transmission of installer identifiers to a third-party request-capture service. Anyone with the webhook URL — including the operator and anyone they share captures with — receives a log of every machine that fat-fingers an install of this name. The typosquat framing combined with the beacon means installers who mistype the target name are silently fingerprinted.

Malicious versions

1 flagged
0.0.1

Indicators of compromise (SHA-256)

0b6925d4c07df297f8cb573df4d85a396794d8793179e7a97f2cfde3aadfcfbc
ea0b26e761c1eb184707d6e8b06e844515bef1de5b38df98f95ba8af16c5a25f

Frequently asked questions

No. gethandler-api on npm has been identified as a malicious package (version 0.0.1 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-005209IN-MAL-2026-005210

References

Credits

  • Amazon Inspector · finder

Scan your dependencies

O3 Security blocks malicious packages like this at install time and in CI.

Supply-chain protection
gethandler-api (npm) malicious package — MAL-2026-5473 | O3 Security