Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

notifier-funcsnpm

Advisory published Updated

notifier-funcs is a confirmed malicious npm package (MAL-2026-10152) that executes malicious code on install (malicious version 1.3.4). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in notifier-funcs (npm)

MAL-2026-10152
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall notifier-funcs

What this malware does

On require, index.js spawns a detached Node child (spawn('node', [...], {detached:true, stdio:'inherit'}); child.unref()) that runs lib/vcall.js. That script fetches JavaScript from the hardcoded endpoint https://api.jsonsilo.com/public/c6c0b393-932f-4ae1-8fca-23c6747f4acc via axios, extracts the.data.model field, and executes it through Function.constructor(...)('require',...), yielding arbitrary code execution on the installer's machine controlled by whoever manages that endpoint. lib/const.js also carries a base64-encoded secondary endpoint decoding to https://jsonkeeper.com/b/ZK45J. The package presents itself as a pino-style logger but ships no such functionality; the exported surface is a cover for the remote-fetch-and-eval behavior. The remote source is a mutable third-party JSON hosting service whose content can be swapped at any time, and the detached-child pattern hides the payload from the parent process.

Malicious versions

1 flagged
1.3.4

Indicators of compromise (SHA-256)

4da033e00206575ad1328031d625b6c6281332e9ecf5514feae6e99cb285d021

Detection & response playbook

Malicious package
  1. Find it

    Search your lockfiles and build artifacts for notifier-funcs (version 1.3.4).

  2. If you installed it — respond

    Remove notifier-funcs from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If notifier-funcs was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.

Frequently asked questions

No. notifier-funcs on npm has been identified as a malicious package (version 1.3.4 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-009648

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks notifier-funcs-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

notifier-funcs (npm) malicious package — MAL-2026-10152 | O3 Security