Your RSA-2048 keys break in 2030. Find every one of them before attackers do.See CBOMkit
Malicious package
quickwinstonnpm
Malicious code in quickwinston (npm) Remove it immediately and rotate any exposed credentials.
MAL-2026-5365
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall quickwinston
What this malware does
The OpenSSF Package Analysis project identified 'quickwinston' @ 3.19.3 (npm) as malicious.
It is considered malicious because:
-
The package communicates with a domain associated with malicious activity.
-
The package executes one or more commands associated with malicious behavior.
Malicious versions
3.19.3
Indicators of compromise (SHA-256)
304b4e430bff604f20121bc97398fa6ee18a25c16187d31b6553248bc54e63c7
Frequently asked questions
No. quickwinston on npm has been identified as a malicious package (version 3.19.3 flagged). It should be removed immediately — do not install or keep it in your dependency tree.
Credits
- OpenSSF: Package Analysis · finder
Scan your dependencies
O3 Security blocks malicious packages like this at install time and in CI.
Supply-chain protection