Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

nolimit-agentnpm

nolimit-agent is a confirmed malicious npm package (MAL-2026-12183) that steals credentials and exfiltrates sensitive data (malicious versions 1.0.299, 1.0.300, 1.0.301…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in nolimit-agent (npm)

MAL-2026-12183
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall nolimit-agent

What this malware does

Package is a weaponized mass-mail / SMS spam and phishing toolkit distributed as an npm package. All 45 source files under.ad/ are post-obfuscated with javascript-obfuscator (string-array + RC4 + self-defending wrappers) per its own scripts.build='node scripts/obfuscate.js' step, and package.json keywords include 'red-team' and 'smtp'. Functionality includes bulk SMTP sending, SMS sending via carrier email-gateways, scanner-evasion features (HTML-attachment redirect obfuscation via base64+JS reassembly, SVG attachments using xlink:href,.url file gateway bypass), open-redirect scanning, and DKIM key generation (templates/functions.txt;.ad/x0.js). A nolimit auth google|microsoft / nolimit contacts flow in.ad/x12.js performs device-code OAuth against Microsoft (hardcoded Azure client_id 9e5f94bc-e8a4-4e73-b8be-63364c29d753) and Google, then enumerates Microsoft Graph endpoints (/me/contacts, /me/people, /me/messages, /me/mailFolders/sentitems/messages) and the Google People API (people/me/connections) to extract the operator's contact list and prior-recipient addresses for use as spam/phishing targets; OAuth tokens are written to local smtps.txt and are not relayed to the author. A license check in.ad/x4.js POSTs {key, hwid, hostname, platform} to http://api.nolimitent.xyz:4100/api/verify and /api/activate over plain HTTP. The Windows-only postinstall (scripts/postinstall.js) is a benign bin-shim creator with no network I/O. The package does not exfiltrate the installer's secrets or run attacker code on install; instead, installing and running it turns the installer's machine and accounts into an instrument for outbound abuse against third parties, with obfuscation specifically engineered to defeat registry scanning.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

47 flagged
1.0.2991.0.3001.0.3011.0.3021.0.3031.0.3051.0.3061.0.3071.0.3081.0.3091.0.3101.0.3111.0.3121.0.3131.0.3141.0.3151.0.3161.0.3171.0.3181.0.3191.0.3201.0.3211.0.3221.0.3231.0.3241.0.3251.0.3261.0.3271.0.3281.0.3291.0.3301.0.3311.0.3321.0.3331.0.3341.0.3351.0.3361.0.3371.0.3381.0.3391.0.3401.0.3411.0.3421.0.3431.0.3441.0.3451.0.346

Indicators of compromise (SHA-256)

9e9510731400dde41fd6705895d15e78bf4fe6f4560162a10bd6016e855f4221
3d95cf53ee52182a3a0cdb73309d759e4236cf56475edc44ec89e7c3e129bbf7
226dafe97e7a6295d574082c71a4033434e09140b80fff47333976498baeee0c
24ee2bea6cae8ef868efdbe61db42abf421a266dfc080ceecc5c8862059a9dba
50f319b5d293c2ac70b74ecae880451b18c87dba21ade539b46feff5d5f3305b
67f76880d08533d7663f6d39f892dd28e07c3a2c5e08523420f99983c3cdd428
6bb0b18aa83b740e2cb908b4dabf469e2447548d637dbc409f1e11f88ab6b534
cb694d8deab4a71176ccf5ead1a24c6717503c52d18c4e48b3d40f1f6c16e86d
e81aefba9555f6328446ba711d855d2d23058d16e95d5d21eb225d469c566cb0
0278c0435e8eeaca2e10042421e76a11302f9ace790eaeaf4fced34e665d8e1c
febc6029c48925cf350d62422fe9b4495396f839662f251b5b1a23c18d0c7ded
d19b806f549f88e088d3f738534042c52ec3b2f56cbea377852ef87a8c03ba0e
080f879e250d90ff81f360f499ce3c065c0138cb9341d870e842f6992e6d3ccf
2c657ecf4611e7ef55cd0d519827e8f36537673169dae669e8db5907d1319082
2e36e306ab470092eef9a91f7904dbea7c57b7054ba7ec29b04f0721a2de9c02
6b28fd56564fc960e15f0bfe31d7ce87aa8154050de7bbd1aff4ad51eb4e653a
a8f5e4a187679a8487a2dff251be15c347b76f8eafc4fee8afeec8ef6c58269e
be52c14fe7fe0845dd1e4500727c1d06c29043457c47033cc54c3e3cbf9a98e8
c8736144b2e441c2f0ad3972fa46f1d212cdde29dfeffe5e13f7e43f660af0a6
693eab24caa59b2bf5623cf0edf987af47a1abb4c5b0b87cecc5bc14a6cec032
d8eec410d0529cfebb36be13a445bcb389e73150c23a6898af73eadc56d0507c
e4d8d2d3eeeb747ee106502689f93d4a1a7544f609f9903b203d4a7a40a0272c
f1a1b773c45c56e16eaa149faaf4543a4b29bc2419c8f463980b6bf5aaecc8c5
f4c18c5b731f995c171f207f6aea105e58e85c33488d0e443333d5f264b29a20
fd1d5f9a5cb02325f9594b9195c57eea1928eaebc8ba742794053374dc1a0b04
0214e2c94c17ce95152e1ad0fc182089da5358dc213969377ad4bb8e4b258343
0db657554b8e8440613509624595b4a5ecf0f43ece744a9c5723df951c2e333b
54604fd6070902cf0ee8155ded3ea5d06fde5307be0faf2955ac29353e161c01
593334222ed0f7a8a72c30dfea7b0767ce502a5b8c23468cc3c1d8929e1d0145
ac3a2209040c6fffbbe1841ac94f4b742b4ed3331ba7744daec36e580212b64a
c0268e8517bf11973a1fe7ecd9f8c0fa5f8d25e77d0518807b15f1e13cee6ec1
8f5769b9a17ffd49ffdca474877ad16bd8608d21ad0a61c12e2316c9aeaf4286
a964c0789c82cbabf1d4ad3860eaca8c1902a44581a7f0d1fe220d3d62204a12
06cfea42bc06fd233e8bf287405dea2a57b2d48b70fb3abe736bd643c0f0d462
3d0e5267547f3e7b8fae2331c0b7b635ec8a4f764cba1fff699fb54edd14cc1e
3ec8331657994da4842e294dcd764e366470da10997c55ca63acc83bbb45cae3
8a99c14841547182edba7deaa4c13061bb5db5b61763be8abbdbae3a2676a1e3
ac90e6036d929f7b5bf2d32c51c42921a9c557f5de4d3e283720dcca5c6e1475
fe35d8a4863298ba66188b43ff75bd029dd372d952aa49cb6eb57bef4f7c39b8
50097018428fc6b74cd2b286e3bfe933ab9e47cc65318509a9c3bbaf9152c89e
c54234dd3321fa56edc001f93494eb149e9a517c5d5b9ac8fee842e9550ddff8
cae15281306d6d5d38e874dd3c162490bd116e7785e251572bd93b0bca51ca39
f40e4ef08502c5143a56191892561b7dc9ae601f24381d8158d8044690049baf
406cdaf4febbe664272dd2dfceec3e80dacba1dda7b0b7fed40760058125dc1f
53e55e00e556761b5ddb3310b66d845da4ece450642c6ac2635fa9b96092c940
17c0700e5e7e6b7e91c82a50070ee22af080ac17530bfaa92104fb225dc7f5af
ed583d76362cbc2889ab3b59db142de0b012da00a5c4df72e145eea571c8ffdc
fc29eb7951f3fda8020c0b5be20641e093e77e8ed628eea64537c115436377e7

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for nolimit-agent (47 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging nolimit-agent across your stack and pipelines.

  2. If you installed it — respond

    nolimit-agent is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If nolimit-agent was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks nolimit-agent before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. nolimit-agent on npm has been identified as a malicious package (versions 1.0.299, 1.0.300, 1.0.301, 1.0.302, 1.0.303, 1.0.305, 1.0.306, 1.0.307, and 39 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-014437GHSA-f9mj-p83x-395vIN-MAL-2026-017724IN-MAL-2026-017722IN-MAL-2026-017716IN-MAL-2026-017715IN-MAL-2026-017721IN-MAL-2026-017720IN-MAL-2026-017718IN-MAL-2026-017719IN-MAL-2026-017851IN-MAL-2026-017852IN-MAL-2026-017837IN-MAL-2026-017825IN-MAL-2026-017841IN-MAL-2026-017856IN-MAL-2026-017836IN-MAL-2026-017844IN-MAL-2026-017850IN-MAL-2026-017846IN-MAL-2026-017847IN-MAL-2026-017839IN-MAL-2026-017822IN-MAL-2026-017832IN-MAL-2026-017821IN-MAL-2026-017829IN-MAL-2026-017826IN-MAL-2026-017834IN-MAL-2026-017845IN-MAL-2026-017828IN-MAL-2026-017848IN-MAL-2026-017833IN-MAL-2026-017859IN-MAL-2026-017823IN-MAL-2026-017849IN-MAL-2026-017854IN-MAL-2026-017835IN-MAL-2026-017840IN-MAL-2026-017838IN-MAL-2026-017831IN-MAL-2026-017842IN-MAL-2026-017827IN-MAL-2026-017853IN-MAL-2026-017843IN-MAL-2026-017824IN-MAL-2026-017855IN-MAL-2026-017830IN-MAL-2026-017820

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks nolimit-agent-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

nolimit-agent (npm) malicious package — MAL-2026-12183 | O3 Security