Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

identityscimapiservnpm

identityscimapiserv is a confirmed malicious npm package (MAL-2026-11061) that steals credentials and exfiltrates sensitive data (malicious versions 4.0.0, 28.0.0). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in identityscimapiserv (npm)

MAL-2026-11061
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall identityscimapiserv

What this malware does

The package's preinstall hook runs index.js, which collects hostname, platform, architecture, home directory, and DNS server list via the Node os module and POSTs the JSON payload over HTTPS to the hardcoded host 367qobrcgbi1dvqrghhhpvham1stgr4g.oastify.com at path /hit. The endpoint is a Burp Collaborator subdomain, an out-of-band interaction server commonly used as a dependency-confusion / reconnaissance beacon. The exfiltration fires automatically on npm install with no opt-in, and the collected fields identify the installer host and its internal network configuration.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

The OpenSSF Package Analysis project identified 'identityscimapiserv' @ 28.0.0 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

Malicious versions

2 flagged
4.0.028.0.0

Indicators of compromise (SHA-256)

811dc4c894f7f73a152e513a54bf6e271e65e76c3345a03ec2359027db0c09b6
7c77102d108de4236b5ff8d121143aaa19efde51a10e4f63a6f79ad2dc982c34
e866098aa6115f837577cc3b24eae409fb1fb67167757f2f0c5517dfa9d8d209
acec636c1ce1c3670c829c8f5b5ebd77b93bb3439b36bf61cb69ca574282439a

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for identityscimapiserv (2 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging identityscimapiserv across your stack and pipelines.

  2. If you installed it — respond

    identityscimapiserv is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If identityscimapiserv was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks identityscimapiserv before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. identityscimapiserv on npm has been identified as a malicious package (versions 4.0.0, 28.0.0 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

GHSA-gv4f-vm3w-7v7wIN-MAL-2026-011115IN-MAL-2026-013289

References

Credits

  • Amazon Inspector · finder
  • OpenSSF: Package Analysis · finder

Detect & block this

O3 blocks identityscimapiserv-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

identityscimapiserv (npm) malicious package — MAL-2026-11061 | O3 Security