Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

google-tag-manager-integration-samplenpm

Advisory published Updated

google-tag-manager-integration-sample is a confirmed malicious npm package (MAL-2026-7294) that executes malicious code on install (malicious versions 99.9.9, 100.0.0). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in google-tag-manager-integration-sample (npm)

MAL-2026-7294
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall google-tag-manager-integration-sample

Malicious versions

2 flagged
99.9.9100.0.0

Indicators of compromise (SHA-256)

11dae8637821566f44d3757c01c8efa9c0c6f59a19003c7e82706f3fa3b75644
fb6a2a42d75e8d9e1b3097a7e1157b090e98a28476692bc4e4b6c6ae5a149ee3

Detection & response playbook

Malicious package
  1. Find it

    Search your lockfiles and build artifacts for google-tag-manager-integration-sample (2 malicious versions).

  2. If you installed it — respond

    Remove google-tag-manager-integration-sample from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If google-tag-manager-integration-sample was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.

Frequently asked questions

No. google-tag-manager-integration-sample on npm has been identified as a malicious package (versions 99.9.9, 100.0.0 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

RLMA-2026-05105RLUA-2026-06265

References

Credits

  • ReversingLabs · finder

Detect & block this

O3 blocks google-tag-manager-integration-sample-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

google-tag-manager-integration-sample (npm) malicious package — MAL-2026-7294 | O3 Security