Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

laycotnpm

laycot is a confirmed malicious npm package (MAL-2026-16253) that steals credentials and exfiltrates sensitive data (malicious version 1.3.10). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in laycot (npm)

MAL-2026-16253
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall laycot

What this malware does

On import, index.js unconditionally calls initialize(), which spawns loader.js as a detached, unref'd, stdio-suppressed child process (windowsHide:true) and writes a.pid file to enforce singleton persistence. loader.js issues an HTTPS GET to https://api.npoint.io/641d37178a880b1e8b8f — a free anonymous JSON-hosting service whose content is fully mutable by whoever holds the bin's edit token — base64-decodes the code field of the JSON response, and executes it via new Function('require','__dirname','__filename','module','exports', decodedCode), granting the fetched bytes full Node privileges including require. The package's declared identity is a cover story: package.json describes laycot as 'all pro layout cat visible smooth' with education/advanced-testing keywords, the README presents it as runtime-utils/image-utils with a fake getProcessInfo API, and the fetch URL is stored in a variable named API_KEY to obscure that it is an HTTP endpoint. The shipped code has no functionality matching any of these descriptions; its sole runtime behavior is the remote-fetch-and-eval loader.

Malicious versions

1 flagged
1.3.10

Indicators of compromise (SHA-256)

888eb7470e3887d76a6ecd9ccb3c635fac2e5c9c2726550b2047f7e52d6c6062

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for laycot (version 1.3.10). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging laycot across your stack and pipelines.

  2. If you installed it — respond

    laycot is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If laycot was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks laycot before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. laycot on npm has been identified as a malicious package (version 1.3.10 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-020132

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks laycot-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

laycot (npm) malicious package — MAL-2026-16253 | O3 Security