Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

ldpbootstrap-jquerynpm

ldpbootstrap-jquery is a confirmed malicious npm package (MAL-2026-5790) that executes malicious code on install (malicious versions 1.0.0, 1.0.2, 1.0.3…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in ldpbootstrap-jquery (npm)

MAL-2026-5790
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall ldpbootstrap-jquery

What this malware does

ldpbootstrap-jquery ships and executes an obfuscated Windows PowerShell payload as part of its documented usage. The package contains dist/ps1-stub.enc.hex, an 8KB opaque hex-encoded blob, and dist/bootstrap.js decrypts it with a hardcoded XOR key (f633ffeeffbbc09da9f2b477e1183294), writes the decrypted PS1 to %LOCALAPPDATA%\Landpage<ps1FileName>, and invokes it via powershell.exe -NoProfile -ExecutionPolicy RemoteSigned -WindowStyle Hidden -File <path> — explicitly bypassing execution policy and hiding the window. bootstrap.js also fetches a session-specific PS1 over plain HTTP from a consumer-configured apiBase (README example: http://192.168.1.143:3001) using MSXML2.ServerXMLHTTP with session/fingerprint headers, then writes and executes it via the same hidden PowerShell flow. The README explicitly documents AV evasion as a design goal, referencing docs/HTA-AV-HYGIENE.md and describing per-session XOR key derivation in an HTA context for MSI delivery. The shipped encrypted blob, hardcoded decryption key, hidden-window/policy-bypass PowerShell execution, and author-documented anti-virus evasion together constitute malware-distribution infrastructure. Although the harmful flow is invoked through the package's API rather than auto-running on npm install or require(), any developer using the package as documented will execute attacker-shaped, AV-evading PowerShell on Windows endpoints.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

14 flagged
1.0.01.0.21.0.31.0.41.0.51.0.61.0.71.0.91.0.101.0.111.0.131.0.141.0.151.0.16

Indicators of compromise (SHA-256)

081cd4ae661f00aaa38c17590d935425f436c732eecba4af50d227c8f4879554
0fd0758eaec7ae489cbbaf58b250db2efc14607c06c2774f2fe7bf64782769fc
67a1d48a2560b4d157c03265d3445ead2ecff56c91769c4fc45e5d8ec06affe8
6f7b8473f32885d965ba7f36c7dd2dca9789a87db43949e35988d75f1926d299
71957c93a274979ca6de0d40b51e8bd32d85592e6a77debf32439c936632cd26
bcab02ae44d1604b6fa9e80156a8c5882f7a4809470ff59eb6d14db4bf28f91f
e1bb4fb444cd0d88009ae97fe127905df0eb1b09436f89e2d4625cbabaab85b4
f10a9875281cbae30c18a5f6a8bcdfd9b4be989a35b7122aff4d7653ca47a20e
0cfe4fa0ac12c2797913fee881e32d32bd0ea715222b3ae9bdfd1fb4bd538139
3e79fb9e25ba591d60c5816768e38c49ec2365e8f1837afd289ffb482b5b24d1
dcd253bbec08e40cc99fa1114972cb96e48134fcd1fdf3bff742e7263ff45d9f
0d0e878cb246d9b78836bde21af3febf7ee52952d1885d064ae347998c96e3e6
2483d2a7cc965487606482d7669013e299c040aa08d28236563ace43d226bf57
54c83e46753941f207f98048001cc8f4adb170f7d840cf9a28f6bae3f5d67fac
64e9e7f7826f87f883aabffe33237ac8df9d95a4ac75455318887f67d5a1c59a
d38f55b7a17efed003ec7fe5b3e177c455b0ac77a09fb6b2e79439df5675c01e
53ae7acf14851d744e4b4de5b5f64026ef962622423d3f244b70ecfef26702dc
c79524dbfad11dfb17e5374e066856ec780480b89857244c73c3bddec79956bf
d4d830c7d6e80ab375b252bd3defe34a79ed3d81b0a866290ada07a7a1991b89

Detection & response playbook

Malicious package
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for ldpbootstrap-jquery (14 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging ldpbootstrap-jquery across your stack and pipelines.

  2. If you installed it — respond

    Remove ldpbootstrap-jquery from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If ldpbootstrap-jquery was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks ldpbootstrap-jquery before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. ldpbootstrap-jquery on npm has been identified as a malicious package (versions 1.0.0, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.9, and 6 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-006504IN-MAL-2026-006497IN-MAL-2026-006499IN-MAL-2026-006496IN-MAL-2026-006502IN-MAL-2026-006498IN-MAL-2026-006503IN-MAL-2026-006501IN-MAL-2026-006500GHSA-2m3g-j8c8-hx83IN-MAL-2026-010651IN-MAL-2026-010646IN-MAL-2026-010648IN-MAL-2026-010647IN-MAL-2026-010652IN-MAL-2026-010650IN-MAL-2026-010637IN-MAL-2026-010649IN-MAL-2026-010635

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks ldpbootstrap-jquery-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore