Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

nativescript-swisspost-pcc-creative-editornpm

Malicious code in nativescript-swisspost-pcc-creative-editor (npm) Remove it immediately and rotate any exposed credentials.

MAL-2026-5793
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall nativescript-swisspost-pcc-creative-editor

What this malware does

Package masquerades as an internal Swiss Post NativeScript package (name nativescript-swisspost-pcc-creative-editor, description literally Security PoC for Bug Bounty). package.json declares preinstall: node index.js. On npm install, index.js reads process.env.INIT_CWD, takes its basename as the installer's project directory name, and POSTs it together with a timestamp to a hardcoded callback URL https://deepbounty.dd06-dev.fr/cb/dc8ee9ff-1372-47c3-b2b6-ce0564ce1f90. Effect on the installer: arbitrary Node code executes at install time and the installer's project name is leaked to a third-party host without consent. Although the author labels it a bug-bounty proof of concept, the package is structurally a dependency-confusion attack — any developer or build system that pulls it expecting the legitimate internal Swiss Post package suffers code execution and information disclosure.

Malicious versions

1 flagged
54.16.3

Indicators of compromise (SHA-256)

a9c9ef8861d14485e696e98c66d95ee5c2a5a608b213841c9c18b254003ae049
c8eca023031e2488506fef1a8b6917bc8a860495d86b3e644595da683f9f77f7

Frequently asked questions

No. nativescript-swisspost-pcc-creative-editor on npm has been identified as a malicious package (version 54.16.3 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-006505IN-MAL-2026-006506

References

Credits

  • Amazon Inspector · finder

Scan your dependencies

O3 Security blocks malicious packages like this at install time and in CI.

Supply-chain protection
nativescript-swisspost-pcc-creative-editor (npm) malicious package — MAL-2026-5793 | O3 Security