Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

node-app-doctornpm

node-app-doctor is a confirmed malicious npm package (MAL-2026-5733) that steals credentials and exfiltrates sensitive data (malicious versions 1.0.1, 1.0.2, 1.0.9). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in node-app-doctor (npm)

MAL-2026-5733
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall node-app-doctor

What this malware does

collect.js gathers host identifiers via os.hostname() and os.homedir(), reads local filesystem state with fs.existsSync, spawns child_process commands, and POSTs the collected data to the hardcoded endpoint http://aab.sportsontheweb.net. The destination domain is unrelated to any legitimate npm/Node tooling publisher and there is no plausible benign reason for a 'node app doctor' utility to ship installer/host telemetry to that host. The combination of system enumeration (hostname, home directory, child_process), filesystem inspection, and hardcoded plaintext HTTP POST to an unaffiliated domain is the standard host-fingerprint exfiltration shape.

Malicious versions

3 flagged
1.0.11.0.21.0.9

Indicators of compromise (SHA-256)

2672da84038326aef670f6e4b5276bc4d1a2f678d986f0a422858bac2a39f6b5
a36bb51486017eff5ce97b5a6c916f6140e0dd1cbfe3f2686bbeb97c03995395
a675df3cebba84e131f74db241a485e0eea07d89837e6fb9d91aac2342713f08
addccbccd4c3c52cd67098a571ed77a4f55ea2303746f421b22b5bbf175a345e
bb98b7bd393ae33a610f2cb95e294878050d42ba2757be857c34e8a411bfec3a
9c131ec8f08bea5eecdaa826ff4a17588c61dc432ca61ef3658dbe0e6b4aebe8

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for node-app-doctor (3 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging node-app-doctor across your stack and pipelines.

  2. If you installed it — respond

    node-app-doctor is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If node-app-doctor was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks node-app-doctor before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. node-app-doctor on npm has been identified as a malicious package (versions 1.0.1, 1.0.2, 1.0.9 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-006316IN-MAL-2026-006315IN-MAL-2026-006312IN-MAL-2026-006313IN-MAL-2026-006311IN-MAL-2026-006314

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks node-app-doctor-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

node-app-doctor (npm) malicious package — MAL-2026-5733 | O3 Security