Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

ng-vzbootstrapnpm

Malicious code in ng-vzbootstrap (npm) Remove it immediately and rotate any exposed credentials.

MAL-2026-1100
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall ng-vzbootstrap

What this malware does

The package ng-vzbootstrap was found to contain malicious code.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

The OpenSSF Package Analysis project identified 'ng-vzbootstrap' @ 1.0.3 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

Malicious versions

3 flagged
1.0.11.0.21.0.3

Indicators of compromise (SHA-256)

2ae6de83bdc46a69c7c92f112a388608f0e19a374168bd75f71ad18f7d6e88d9
da191c637225627fd72d8ac07b5358e97dad12fa37eb8cd67aaff06686d5fbd6
8e3edec659665a66e3b038b43eef43aa20405b14a4b4d47323636a8e3ae352aa
55334ed89dc8f6a03c48fe6f25e59230be73683c13ecc51950eea3db94608b41
c5f868642d9c32305da4277fef20c77ac8268459705785fa34a39093a456fe6f

Detection & response playbook

Malicious package
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for ng-vzbootstrap (3 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging ng-vzbootstrap across your stack and pipelines.

  2. If you installed it — respond

    Remove ng-vzbootstrap from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If ng-vzbootstrap was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks ng-vzbootstrap before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. ng-vzbootstrap on npm has been identified as a malicious package (versions 1.0.1, 1.0.2, 1.0.3 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

GHSA-25jj-4j8c-cgrqRLMA-2026-01452RLUA-2026-01794

References

Credits

  • Amazon Inspector · finder
  • OpenSSF: Package Analysis · finder
  • ReversingLabs · finder

Detect & block this

O3 blocks ng-vzbootstrap-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

ng-vzbootstrap (npm) malicious package — MAL-2026-1100 | O3 Security