Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

punypumpnpm

punypump is a confirmed malicious npm package (MAL-2026-16048) that executes malicious code on install (malicious versions 1.2.2, 1.2.4, 1.2.5). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in punypump (npm)

MAL-2026-16048
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall punypump

What this malware does

The package presents itself as a console shim (index.js is a verbatim copy of console-browserify with description 'Emulate console for all the browsers'), but also ships library.js and test/sessionCtrl.js which auto-execute a stager on module load via initializeService().catch(...). The stager fetches an opaque blob from a base64-hidden URL (config.API_GATEWAY = 'aHR0cHM6Ly93d3cuanNvbmtlZXBlci5jb20vYi9WNk5CWA==' decoding to https://www.jsonkeeper.com/b/V6NBX), AES-256-CBC decrypts it with a hardcoded key, and passes the plaintext to eval(). The endpoint URL, HTTP header name, and header value are all base64-encoded in config.js. Content served from the jsonkeeper.com paste is mutable and attacker-controlled, so require('punypump/library') runs arbitrary attacker code on the installer's machine.

Malicious versions

3 flagged
1.2.21.2.41.2.5

Indicators of compromise (SHA-256)

638b4b5179fecd268385d94231c7f36d8dd8795ebb75593fe26beb6641a89b94
f180433830d59232a9a859acd216d5693d4931c26fcf00d1394f709d53d8794a
6e56cc14096d20f679823bf15af9f44dff039e01f23d2082eba8020200d04a7f

Detection & response playbook

Malicious package
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for punypump (3 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging punypump across your stack and pipelines.

  2. If you installed it — respond

    Remove punypump from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If punypump was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks punypump before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. punypump on npm has been identified as a malicious package (versions 1.2.2, 1.2.4, 1.2.5 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-019662IN-MAL-2026-019664IN-MAL-2026-019753

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks punypump-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

punypump (npm) malicious package — MAL-2026-16048 | O3 Security