Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

metrics-pipeline-d8k2npm

metrics-pipeline-d8k2 is a confirmed malicious npm package (MAL-2026-5858) that steals credentials and exfiltrates sensitive data (malicious versions 1.0.0, 1.0.1, 1.0.2…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in metrics-pipeline-d8k2 (npm)

MAL-2026-5858
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall metrics-pipeline-d8k2

What this malware does

Package declares "postinstall": "node run.js" in package.json, causing automatic execution of bundled beacon scripts on npm install. beacon29.js loads child_process, https, and fs, reads files via fs.readFileSync and reads process.env, gathers host identity (process.platform), and POSTs/GETs the data to remote endpoints; it also references https://registry.npmjs.org and https://npm.pkg.github.com, consistent with credential/token harvesting and potential self-propagation through registry APIs. beacon_linux.js mirrors the pattern on Linux: require('child_process') + require('http') + os.hostname() + os.platform() followed by http.request(...) POST to a remote host. The package's stated 'metrics pipeline' name is a cover; the only behavior on install is host fingerprinting and outbound exfiltration. Installing this package on a developer or CI machine causes immediate compromise: environment variables (which commonly hold cloud and CI tokens), file contents, and host identifiers are sent to attacker-controlled infrastructure without user interaction.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

21 flagged
1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.81.0.91.0.101.0.111.0.121.0.131.0.141.0.151.0.161.0.171.0.181.0.191.0.20

Indicators of compromise (SHA-256)

01ad2ee3d3807102a3f02c01af0d3fec46d91e9764eb77a8bcedf9c6be7fc3b0
54c1af327fbf53a18b26a293093ff11b2ac19e346468fca66ff083166972dc7f
5b0d9377de514d01f4b2c4007ca1d7dfd5787ab72c185eb74a6f4f53ac1658ba
89a516af939e2a8520621d9ef7f847517da94269623a71aea9f2f00d3188a954
c113970b47b623dedfa59e8ff71bf20bfca793e1e1d9ff76b29eca1bf674dc9f
3a44ea64194cd8e1b678076116fadf8bc05e764bb8d478c72266cd0bf3874da4
3bbe5b8c8642c0c20bdd53879e0aea8ac95003d0f4d23611524ecffcef12acde
5c656acf9f196c5089baacf11db8aa87dfed701ae203199729a68206227f11f0
b10e688de4ddf8c6a9697553b78d365293a2180c05977a38cbf899cddee3e62d
bd50e0a34295875e7f64e50db862fce861a0a315f2ea1103df52eefc2ca78c48
e52e5a5c05cceaf09f75cab7a4fdfde26cad46a186d15afc2b8be672c2827b01
eab49ef22bb82edc216799d801a682c984a9866c6641ea309b858ad67fe56aba
1f40e8efc2eedc3f971b3ee2ece3f4ef2c0bfe520b5b8c9ecf0fb5801ad03a50
367ed35f72559e7378a3550ef103a3901a34159a89c7cf96396451d1aaeda423
f51f84544dd6aa3cf55dcdaa1778df99eb19b6f2be0a57772ff907629936da55
7748df10c51a36e3514811f29c5a5675099e5da683e2dc51e672273699b99860
ae12e4f82e5f5f66cbf8c524d6d1c8435f989f639f9ad42a454f63e8247020ef
2412c76c582f149d5e9b2fa87d33018965031c8f5e9a5469085f52dfcf52c346
3e33670cb9a2bdee78c42193d6f256c05bebea69ac8879fb434a291c27595e45
db8fb1276f5fa18fa71d68408d3413206947eb0160cdb4fba5fc468a95fe39d8
fd0b7f1a17cdabf968bdc3ab51ec486aa2c88e749deee0a30da7ad8b5fdea266
8376ac5cff648426d3d11d8a4937fbf250d55b3c72127670d556329585420992

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for metrics-pipeline-d8k2 (21 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging metrics-pipeline-d8k2 across your stack and pipelines.

  2. If you installed it — respond

    metrics-pipeline-d8k2 is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If metrics-pipeline-d8k2 was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks metrics-pipeline-d8k2 before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. metrics-pipeline-d8k2 on npm has been identified as a malicious package (versions 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, and 13 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-006723IN-MAL-2026-006726IN-MAL-2026-006722IN-MAL-2026-006724IN-MAL-2026-006727IN-MAL-2026-006725IN-MAL-2026-006815IN-MAL-2026-006809IN-MAL-2026-006814IN-MAL-2026-006812IN-MAL-2026-006813IN-MAL-2026-006810IN-MAL-2026-006816IN-MAL-2026-006811IN-MAL-2026-006831IN-MAL-2026-006857IN-MAL-2026-006851IN-MAL-2026-006850IN-MAL-2026-006896IN-MAL-2026-006897IN-MAL-2026-006895GHSA-77q5-c2w3-pc44

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks metrics-pipeline-d8k2-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore