Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

notafollower122npm

notafollower122 is a confirmed malicious npm package (MAL-2026-14035) that steals credentials and exfiltrates sensitive data (malicious versions 1.0.0, 1.0.1, 1.0.2…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in notafollower122 (npm)

MAL-2026-14035
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall notafollower122

What this malware does

package.json declares a postinstall lifecycle script that runs automatically on npm install. The script uses child_process to query the AWS ECS container metadata endpoint (ECS_CONTAINER_METADATA_URI_V4/task), which returns the cluster name, AWS account ID, task ARN, and container image list for the installer's ECS task, then POSTs the response body to the hardcoded ngrok tunnel https://mourner-slot-explicit.ngrok-free.dev via curl -X POST... --data-binary @-. The package ships only package.json with no source, build artifacts, or documented functionality, so the postinstall has no legitimate purpose. The destination is an anonymous, mutable ngrok tunnel with no relationship to any publisher — the shape of cloud-environment reconnaissance and exfiltration against AWS ECS installers.

Malicious versions

8 flagged
1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.7

Indicators of compromise (SHA-256)

178cf86e67d7e73598f89c87bba22ba5f1958f2ee5cd45ecdaf9b1ba5268cb15
b451f9369b95739fc7fe451fbdfe69d081377be39bf369256ca3057e5a0feb4e
cbf6ebd17b62df1bfea09ad1145a8663b8122de3daae1e769bb6837921ee023b
d8da1f6c3ab8d69c06e10e93d1f332d2dbef43f464e1ac5a58277ba5928fd39d
1c626a6b7d7217607c681cea011862a9979c32219afc0adc67b165077423d46f
4a88c0751cf600b776cdd64c515a2538fdc7493c4b93bf204cf767cf9a1cfec7
83409fb8c0dc76764a944064219de6a4d59d6b24413db5e36d897681f3183add
b3bb7cfaa81bb48f095685c07a30fe289560ea50ce277cbc2978b1fcbe9a3521

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for notafollower122 (8 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging notafollower122 across your stack and pipelines.

  2. If you installed it — respond

    notafollower122 is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If notafollower122 was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks notafollower122 before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. notafollower122 on npm has been identified as a malicious package (versions 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-017727IN-MAL-2026-017777IN-MAL-2026-017735IN-MAL-2026-017779IN-MAL-2026-017748IN-MAL-2026-017746IN-MAL-2026-017740IN-MAL-2026-017733

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks notafollower122-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

notafollower122 (npm) malicious package — MAL-2026-14035 | O3 Security