Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

mkb-managernpm

Advisory published Updated

mkb-manager is a confirmed malicious npm package (MAL-2026-14490) that executes malicious code on install (malicious versions 1.0.10, 1.0.11, 1.0.12…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in mkb-manager (npm)

MAL-2026-14490
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall mkb-manager

What this malware does

The package was found to contain malicious code or consuming dependency that contains malicious code

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

6 flagged
1.0.101.0.111.0.121.0.131.0.141.0.15

Indicators of compromise (SHA-256)

299f162cc2ff57788cc4ebadedda746bfd504ac2a63fb53a3789a53c2e1881c9
27bc086d2159cad3d4eb02427ea2daa5f66ad57c39cbbaad5a8bb367071f4fb7
67bea27cdd622f8703f0d89fac590cc56bc3bd380d7238c1dcc46edfb7255e13
76ea22165898755e62243e43859726360d98e865cb36252c0a6c7df7e16eed29
f66b9c2609c0e3a3ef16bf9eeb060cb3d2c056ac0a27dc338b8e3fa2b5199218
f70f443a1e0f442e8de394d660a73d162e7e283ceb57b3097baba0e2aa3ec55b
f8f7be4f33df81a5ad0c39163ca837d90d4e0b4293f4f096d121926a724328c1

Detection & response playbook

Malicious package
  1. Find it

    Search your lockfiles and build artifacts for mkb-manager (6 malicious versions).

  2. If you installed it — respond

    Remove mkb-manager from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If mkb-manager was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.

Frequently asked questions

No. mkb-manager on npm has been identified as a malicious package (versions 1.0.10, 1.0.11, 1.0.12, 1.0.13, 1.0.14, 1.0.15 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

GHSA-wvpv-8v52-pgq7IN-MAL-2026-019269IN-MAL-2026-019264IN-MAL-2026-019268IN-MAL-2026-019266IN-MAL-2026-019267IN-MAL-2026-019265

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks mkb-manager-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

mkb-manager (npm) malicious package — MAL-2026-14490 | O3 Security