Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

gs-uitk-lodashnpm

Malicious code in gs-uitk-lodash (npm) Remove it immediately and rotate any exposed credentials.

MAL-2025-192377
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall gs-uitk-lodash

What this malware does

The package gs-uitk-lodash was found to contain malicious code.

The OpenSSF Package Analysis project identified 'gs-uitk-lodash' @ 35.3.3 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Malicious versions

4 flagged
33.3.335.3.335.9.936.0.0

Indicators of compromise (SHA-256)

c89a6d85d1019b9d98f88e94d18fd4ec4ae045bd6f941941e9bdde517a749fdd
feecd7d802ec19931f6a91819521c5409d84adc3ee12e026f16c3f2df1384d9c
46e71552359a176c9f4bc6782c7b12187277a490a81a2881048183f04ab8b68c
2de2e606bc9fde8de540caf63cbded837e1bbbd7bc6bd2d477e38dcf89a76f0b
5109d6f496cd17ca9aded3a571a11af77a39e9f7662a839406e290e959b4a409

Detection & response playbook

Malicious package
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for gs-uitk-lodash (4 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging gs-uitk-lodash across your stack and pipelines.

  2. If you installed it — respond

    Remove gs-uitk-lodash from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If gs-uitk-lodash was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks gs-uitk-lodash before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. gs-uitk-lodash on npm has been identified as a malicious package (versions 33.3.3, 35.3.3, 35.9.9, 36.0.0 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Credits

  • Amazon Inspector · finder
  • OpenSSF: Package Analysis · finder

Detect & block this

O3 blocks gs-uitk-lodash-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.