Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

nodemon-gulpnpm

nodemon-gulp is a confirmed malicious npm package (MAL-2026-10065) that typosquats a legitimate package to trick installs (malicious versions 3.1.14, 3.1.15, 3.1.16). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in nodemon-gulp (npm)

MAL-2026-10065
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall nodemon-gulp

What this malware does

Package is published as nodemon-gulp but its contents are a verbatim copy of the upstream nodemon project: package.json declares author: Remy Sharp, homepage: https://nodemon.io, and bin: { "nodemon": "./bin/nodemon.js" }, so installing this package places a nodemon shim on the user's PATH supplied by an unrelated publisher. package.json also declares "ts-webplug": "3.0.5" as a runtime dependency, yet no file under lib/ or bin/ ever require()s ts-webplug. The only effect of declaring this dep is to silently pull ts-webplug into the installer's dependency tree on npm install, where its lifecycle and import-time code can execute. This is the canonical namespace-abuse + typosquat-loader shape: a clone of a well-known package, republished under a confusable name, used as a vehicle to deliver an otherwise-unjustified third-party dependency to anyone who installs it.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

3 flagged
3.1.143.1.153.1.16

Indicators of compromise (SHA-256)

04b5ac5c522b156a64f943a2d8e2dfd170230d0a23ac0bae5ada0945c7aee4c7
bf7d5e881aed308912128dc41892a1e12dbedfd29ced5195ff2078be80dc6302
1a68e6ed75a1a481de7133f9eca82d2584a52abd2ab0f82df4f688ddfb2c2e55
18cfb051ae84a8ed00bba3ae1eaf7720ec6479a402ae0540c6d66a7fa304f52a

Detection & response playbook

Typosquat
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for nodemon-gulp (3 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging nodemon-gulp across your stack and pipelines.

  2. If you installed it — respond

    nodemon-gulp is a typosquat — you almost certainly intended a legitimately-named package. Remove nodemon-gulp, install the correct package, and rotate any secrets exposed during the install since post-install scripts may have already run.

  3. Did it already run?

    If nodemon-gulp was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks nodemon-gulp before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. nodemon-gulp on npm has been identified as a malicious package (versions 3.1.14, 3.1.15, 3.1.16 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-009167GHSA-wqr5-5c9r-9rj7IN-MAL-2026-009609IN-MAL-2026-009608

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks nodemon-gulp-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

nodemon-gulp (npm) malicious package — MAL-2026-10065 | O3 Security