Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

ollama-helpersnpm

ollama-helpers is a confirmed malicious npm package (MAL-2026-6581) that steals credentials and exfiltrates sensitive data (malicious versions 0.1.0, 0.1.1, 0.2.0…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in ollama-helpers (npm)

MAL-2026-6581
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall ollama-helpers

What this malware does

scripts/postinstall.js executes automatically on npm install and performs a bulk harvest of installer-side identity and configuration data: OS hostname and username, ~/.gitconfig user email, recent committer emails parsed from.git/logs/HEAD, SSH public-key comments from ~/.ssh/*.pub, GitHub identity from ~/.config/gh/hosts.yml, GCP project/account, AWS profile names from ~/.aws/config, DNS search domain, CWD, CI provider, and parent project package.json author/repo. The collected JSON is POSTed via https.request to the hardcoded endpoint npm-package-logger-228835561205.europe-west1.run.app, an anonymous Google Cloud Run host unrelated to the package's claimed homepage (ollama-js.dev). The package additionally impersonates the Ollama ecosystem with fabricated publisher metadata (author 'Ollama JS Dev', homepage ollama-js.dev, repo github.com/ollama-js-dev) — none of which belong to the official Ollama project at ollama.com / github.com/ollama. The declared main (dist/index.js) is not shipped in the tarball; the only executable surface is the postinstall data-collection script, confirming the package is a pure exfiltration vehicle dressed as an Ollama helpers library. The 'telemetry' framing in the script is a cover story — scope (SSH key comments, committer history, AWS profile inventory, cloud account identifiers) far exceeds anything a legitimate version/platform telemetry beacon would collect, and no consent prompt or opt-out exists.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

23 flagged
0.1.00.1.10.2.00.2.10.3.00.3.10.4.00.4.10.5.00.5.10.6.00.7.00.7.10.8.00.9.01.0.01.0.11.1.01.1.11.2.01.2.11.2.21.2.3

Indicators of compromise (SHA-256)

3f3531b5d58d5b2f2458c55fb8d72e35c63d40238a7774ecb6975f0e8ff326e8
52323ef2a3908b7db1565ae149128d053363ab2612c7bc3a938c3f2d63c285cf
4842244ede067e7f1c6fa07a21636f5d8c0f41f292a77d4fbbd29ce68f5cb417
89f19ba6818204523bd823628c07bf3c886616794089498b43a42d7877b08a36
96de23b2b7b4768246fe25cc586cbb0781f15d8f69546a6a0f584cdfe6f4a88d
c1e85848fe916dc9949b222e4ca5eb73ca632226d4b12eda8eb37b5c41f45424
c321a68602633b07a52ad2418b7e4133f0c5da6ebc8c7f6ea7943fb1866fadd6
68ff4cb46144415c05d0944b52234bba4551c847f363f51e674ec77e18c54dd1
7fd991ddb23d7dc8cb92c0591d7daca16e681c5e9714d332807c319ebb9cd9d4
c6097efed49933530a35aaf1d08bf000b0204bd69aafa2e84fb082162bcf1334
db06cbeb10fe09ae52a1a10aeb267a33ea9b86c0e7f0b94dbad85215f691feb7
ed2abc839f6d437bd3b5e09db5facae18c3c43ade44d73b1f537f322d29ab2a3
f11e8d613d4f7c3b35fa1377006b5d8bc1fe885f751c714a786d0fdd76dd7151
3d424beeb7b25001d549a3fd9538839f683c76afe489a40997a924f79d6ddc6b
63fc715183670040c0637637139534ff731dbfda5ac60fcb261a1b9927d9edb2
64c2c80324eee4f81162c691f5dd842e7f8cb084fd29cfb47fb26104d474d511
6a84e22df207c28fe4ea408511d7bdc7dc0872289d3f2d7be571f891f2adf822
dfc4698aa6f37e9c78453e74ace2f2c07438cb4318a7662cdfd3312d75f8bf66
f519c77103ceb28e34f753c15bdd3ff8f8d0695e487a9221f0a0ca7d8f8dc90b
39732261297a9eb51344a91479c71ce2adb2fb4b833305ac1a2c1dea8ea59a49
3f28032527991ea37afbaa3d7f53684ab3617cff7fc260b54265d3ddaee04b5b
7324e3cb1cdfc9bfb9cbf761b759508d02f7d420d9b3cf58061ee2c972b43c87
b0dcc19feb9c952b99f0c1d63bc82d20b92026301f855e69b1849b8a93716062
b896f4d0b17d3c0eca385ea0f818a175bd6eefb37ae80c7574956ac08cd072c9

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for ollama-helpers (23 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging ollama-helpers across your stack and pipelines.

  2. If you installed it — respond

    ollama-helpers is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If ollama-helpers was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks ollama-helpers before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. ollama-helpers on npm has been identified as a malicious package (versions 0.1.0, 0.1.1, 0.2.0, 0.2.1, 0.3.0, 0.3.1, 0.4.0, 0.4.1, and 15 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-007756IN-MAL-2026-007757GHSA-73pg-hv45-6r54IN-MAL-2026-008266IN-MAL-2026-008272IN-MAL-2026-008265IN-MAL-2026-008263IN-MAL-2026-008271IN-MAL-2026-008269IN-MAL-2026-008261IN-MAL-2026-008267IN-MAL-2026-008268IN-MAL-2026-008274IN-MAL-2026-008270IN-MAL-2026-008260IN-MAL-2026-008273IN-MAL-2026-008264IN-MAL-2026-008279IN-MAL-2026-008280IN-MAL-2026-008275IN-MAL-2026-008277IN-MAL-2026-008278IN-MAL-2026-008281IN-MAL-2026-008276

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks ollama-helpers-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

ollama-helpers (npm) malicious package — MAL-2026-6581 | O3 Security