Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

nolimit-xnpm

nolimit-x is a confirmed malicious npm package (MAL-2026-4621) that steals credentials and exfiltrates sensitive data (malicious versions 1.0.194, 1.0.197, 1.0.216…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in nolimit-x (npm)

MAL-2026-4621
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall nolimit-x

What this malware does

nolimit-x ships an entirely obfuscator.io-packed runtime (45 files under.ad/, including the x0.js entrypoint) with no readable source, and devDependencies + the build script confirm the obfuscation is intentional (build: node scripts/obfuscate.js, javascript-obfuscator in devDependencies). The decoded entrypoint exposes a CLI offensive toolkit: a send subcommand for bulk SMS via SMTP-to-carrier email gateways and bulk email; an auth subcommand performing OAuth device-code flows against Microsoft and Google to obtain SMTP + Microsoft Graph credentials; an extract subcommand that reads a victim mailbox's contacts via Graph + IMAP and writes them to disk; a web subcommand that injects a sending panel into a logged-in Chrome webmail tab; a dkim subcommand that generates DKIM keys for arbitrary sender domains; and scan-redirects. README markets it as an "Advanced email sender" with keywords including "red-team" and "smtp". A hardcoded license check (http://api.nolimitent.xyz:4100/api/activate) POSTs hardware ID, license key, hostname, and platform in cleartext when the operator runs license-gated subcommands. main and bin both point at.ad/x0.js, which calls program.parse() at module top level — a consumer that require()s the package will run commander against the consumer's process.argv (no network fires until argv matches a subcommand, but the library/CLI conflation plus pervasive obfuscation make pre-install audit infeasible). The package is a packaged phishing/spam/credential-phishing toolkit dressed as an npm library; installer-side harm is bounded (no auto-exfil at install or import), but the package's purpose is to enable attacks on third parties (mailbox owners, SMS recipients, OAuth account holders), and the obfuscation defeats normal supply-chain audit.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

41 flagged
1.0.1941.0.1971.0.2161.0.2201.0.2271.0.2361.0.2391.0.2401.0.2561.0.2621.0.2631.0.2641.0.2651.0.2661.0.2671.0.2681.0.2691.0.2701.0.2711.0.2721.0.2731.0.2741.0.2751.0.2771.0.2781.0.2791.0.2801.0.2811.0.2821.0.2831.0.2841.0.2851.0.2861.0.2871.0.2881.0.2891.0.2901.0.2911.0.2921.0.2931.0.294

Indicators of compromise (SHA-256)

285e977ba4c80fcc1909bd9674ebb12f22d4fbb17431151b6237403d7ac570ed
ee66863b52eb9cbf1d5e0c370cbac5dfff7a8cc34605d74523bea57f10b5bbea
fc9b808348f8faf797b0aedc8863482566b3d4a244c20c65f2e65632627a87bd
5981a3115393441426b90bb57bd7453e51aabc5979a44faf9cccda8c3300dadf
23ed599e9d8a9e980462d4ebb0a2307b855227945549a93148525453c3dabeae
80ca928c2d7cad845bcb464915d0054f3df368814318d4ccf1ddcc33d2ed1923
b16185122ae13b6bd8cd7cc837ba7bf1223a6728160eaa3c8b5f2dbc35c57405
d6153371f83d2cd05658b0a6c2692dfdfef43ec5c538b58fae43485bb324eb1b
d707992010c289b472218e2d8342de97c8e874c1deab297bd3267b7c196173eb
dc3f769bee8b5c1ad848b374a51b148e9173802004fe182fa3953ef3418b517c
078e1232e1d63a83c4fca84c9bf0c9c543eeebe494af4f9e475ce4a83c421e8b
12fbda074cf4716a407325f9571ea93c2ebabc3602552fde99b65b965d1d37ca
a9273ce626498a8ddee3d7270ba0c4a870f2d0582bc16ea1c19ff5e9d2c2e7d2
aa807efa930f3e0063300471ffc59b70fdd336e0f99b3b395d57e0f4fa27f252
9d95c9f17d124de75eaa2caa15f790beceac22bb5f026304fb9515e4e4de67cc
19c4775fdb5f1abc5e171c4b5b486833271c45566a6bf6ee12c0ad25bc4f7425
1b83f545fb498def872b8da5c7145119bb7c45e8a883a8e9bf7fbbe437f2a4f4
1ecb7a13ea06404ba255dfce5317b9c5b07a89f0d8c6d0692b04f2e2aaf65b9a
5ac439a7b8406d37ea24065f0d9e9ad8481c6f2d90a293958e99a18c8655c6f1
92a244ab5171edadc3082bc97d5b0834c4cfe98f2e5b6437503a30a7c1ac38aa
fbfe803215201c4a9d944a516d3c94943f0374ce195ee7aed246959478bccc7c
745d1ae1e6be91a5ada1794f0662d2eda24c14ef0cfbb27dcaa8f0cab21a7d50
75aaf6fe9ffd8ed13b946abcc11c2d7968ae18b3adef425feb0029ae0bcc1931
c190144fa33ad8cdc5bb4263fe0c4917fa80fdb42f334aac681496548ff6aa7c
ca8b7d13f1a6ef614bd9d38cb638f4b1944eb4d2c0565a3373db01abbb883477
1a9c66d1394323806adccc710c636f9ea7ce0b2024663a5a783bc11510264dc7
ccf60ba7ea5c4024535d8fb6006c06a6dc0c2bcd9f617d93f9f4bc07386f609b
7d1d9766b7781f13fab27644cdecbbbfc7e5b478f3fafb04a1feac784fdae7d1
e2765c6badfb91b19449183f07214d49780f55f6b6db31947d8d1f3dd36f80df
c54737039d031bd0ffcd911bab3e80b870f25e0f987331774e4f9d0e731656cb
d2ef46a3ae9a00f65bcd176871cc77883aa2465b5c316b61a4d054faa79b921f
2512179e2b23315f172b895f88df63ae7b53baabecb49df4ac56a4f299b28202
2ec721f6ed045d9dfeeb9a9c6af50cf44d7e2417a5811364956600324579edd8
75121c30d21373d20db6105ed76c6bedd3928aaa1caeb124cc0b0094c7d73115
b37378c97a6d41ee9558396d7a774792d2e1feba4e80a92d106823299fc6ebb8
0fdb108b2213dd18e686c76b718e59fdb92b36d336c8fb5f68ee938581a97fff
a43b13325bc6ee1a856a95e5db6cbcfc500c674b05225adc3469c9428d975c1b
e2df85ae9fbab386c67f60877990b9ca94a65263707fc0e89e4b50f2ec8a4f05
05865c5e166977a49c2ac63f0322f4bfd0bc0c0ba7a49c2633d4bf5f919cca84
24f786a4210bb2613c9e25860e5e9e0d2603d6ed2a1fe69e01b9588fcf1939eb
5da1387db0097816e091215735c620e2e040a7fd1206116359006ceef2f372a7
99915bb3bad90959844f085b34f50cff96a2220693fc8829060ce463c03f83f2
709156b25ca8b29a55594cfcee4808f6b7fdd48ffe4b2461f30308755d93041a
0b580a282bb1eabe66b731f2943c6bbfdec739d3b95aa54775793f021e7a84c5
0bc68f764887ef1f6effe636b99fe7750caa702b1686c4162cc98102b2f5ff43
25d5212729267455d9247c9a16f860a8e686d144ef044fa0ad48b8903190496d
77669879da34cace3465decede2c93fc430ffebaa7c7c29119cecb204059f0c6
8cd0f6bb974a8a4a70a3be4a4cc7e81e2a1f1373126735aa7ce96ab2791ad1b7
a98e4a68025cbb93b8373169d4532a262217b59116619bea25acc11f03c246c6
fee2baff97f4aa2a6a31b45e0b9b74cbe5f9dadea32f1c72bf599fdd41ed535f
4b70b590ade63e0307933fe4959266ba5bb7bd3920406ca2a9094af5ecfbb38b
887f0943b1ca16eb3b49bbb9fe25775fc8994a540383d742bcc1927445274feb
ada274572539c997c5c7e3280a112be5bfdedd77252b3e81ecc951a936539c7d
ba893babd6ba170e52cf486c6588c7c50648d9476fb1c05c42e289d884ced12d
f7a74ce0f50e8539dfdbbbb62c81d9f2493b0415789658a04ed4387a752eb2b6

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for nolimit-x (41 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging nolimit-x across your stack and pipelines.

  2. If you installed it — respond

    nolimit-x is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If nolimit-x was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks nolimit-x before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. nolimit-x on npm has been identified as a malicious package (versions 1.0.194, 1.0.197, 1.0.216, 1.0.220, 1.0.227, 1.0.236, 1.0.239, 1.0.240, and 33 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-003509IN-MAL-2026-003508IN-MAL-2026-003507IN-MAL-2026-003510IN-MAL-2026-006065IN-MAL-2026-006063IN-MAL-2026-006047IN-MAL-2026-006060IN-MAL-2026-006052IN-MAL-2026-006055IN-MAL-2026-006068IN-MAL-2026-006049IN-MAL-2026-006054IN-MAL-2026-006058IN-MAL-2026-006059IN-MAL-2026-006048IN-MAL-2026-006066IN-MAL-2026-006056IN-MAL-2026-006064IN-MAL-2026-006051IN-MAL-2026-006050IN-MAL-2026-006067IN-MAL-2026-006053IN-MAL-2026-006057IN-MAL-2026-006062IN-MAL-2026-006061GHSA-cp8c-2xwh-q227IN-MAL-2026-008973IN-MAL-2026-008981IN-MAL-2026-008937IN-MAL-2026-008936IN-MAL-2026-008990IN-MAL-2026-008942IN-MAL-2026-008941IN-MAL-2026-008940IN-MAL-2026-008938IN-MAL-2026-009002IN-MAL-2026-008949IN-MAL-2026-009009IN-MAL-2026-009008IN-MAL-2026-008948IN-MAL-2026-008944IN-MAL-2026-009007IN-MAL-2026-009387IN-MAL-2026-009382IN-MAL-2026-009380IN-MAL-2026-009383IN-MAL-2026-009386IN-MAL-2026-009385IN-MAL-2026-009384IN-MAL-2026-009377IN-MAL-2026-009378IN-MAL-2026-009376IN-MAL-2026-009381IN-MAL-2026-009379

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks nolimit-x-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

nolimit-x (npm) malicious package — MAL-2026-4621 | O3 Security