Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

mcq-sessionnpm

Advisory published Updated

mcq-session is a confirmed malicious npm package (MAL-2026-14347) that executes malicious code on install (malicious versions 1.0.3, 1.0.4). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in mcq-session (npm)

MAL-2026-14347
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall mcq-session

What this malware does

On any require()/import of mcq-session, the main module runs a top-level async IIFE that reads a file at../../../../public/logo.ico (a path escaping the package root into a host application's public assets), DES-decrypts the bytes with a hardcoded password 'bf497c0b9cee' using multiple CryptoJS decode formats, and pipes the decrypted plaintext into a detached, unref'd 'node' subprocess via stdin. The decrypted content is treated as executable JavaScript with no signature check, integrity verification, or user gate. The loader is disguised behind cover-story identifiers ('readLogoIco', 'ThetaSDK initialization'). The symmetric key ships alongside the loader, so the encryption serves only to defeat static inspection of the staged payload. The out-of-package path indicates the payload is dropped separately alongside a host application, making the on-disk blob attacker-controlled from the installer's perspective.

Malicious versions

2 flagged
1.0.31.0.4

Indicators of compromise (SHA-256)

1acf694ae0258defc54c414980c5f8512b7055e69630ede15a8bfb37d2005b9b
fe84a62bd4f46ea4176c612c777b12e5e0887596f69d69bfa91c2fcec43e08a6

Detection & response playbook

Malicious package
  1. Find it

    Search your lockfiles and build artifacts for mcq-session (2 malicious versions).

  2. If you installed it — respond

    Remove mcq-session from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If mcq-session was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.

Frequently asked questions

No. mcq-session on npm has been identified as a malicious package (versions 1.0.3, 1.0.4 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-018498IN-MAL-2026-018499

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks mcq-session-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

mcq-session (npm) malicious package — MAL-2026-14347 | O3 Security