Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

ranux-devnpm

ranux-dev is a confirmed malicious npm package (MAL-2026-14259) that steals credentials and exfiltrates sensitive data (malicious version 5.0.0). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in ranux-dev (npm)

MAL-2026-14259
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall ranux-dev

What this malware does

package.json declares the dependency @whiskeysockets/baileys but resolves it from github:rcedubot/X instead of the npm registry. Installing ranux-dev pulls arbitrary, unpinned, mutable code from that personal GitHub account under the name of a widely-used WhatsApp Web library, and that code runs in the installer's Node process with full WhatsApp session and credential access. Every shipped source file (index.js, config.js, database.js, tenantManager.js, command.js, lib/.js, plugins/.js) is heavily obfuscated with obfuscator.io-style transforms and an RC4-over-base64 string decoder, so endpoints, credentials, and control flow cannot be reviewed statically. config.js exports a frozen SECRETS object with hardcoded encrypted strings alongside API_ENDPOINTS and NETWORK_CONFIG (MongoDB-shaped) constants. The combination — dependency substitution of a popular WhatsApp library from an unaffiliated GitHub account, uniform obfuscation across the tarball, a multi-tenant WhatsApp/MongoDB architecture, and shipped hardcoded credential-shaped constants — matches the session-harvester pattern in which installer WhatsApp sessions and tenant data are funneled to an author-controlled backend.

Malicious versions

1 flagged
5.0.0

Indicators of compromise (SHA-256)

4dde928a7de2064f13b18847a56607605bd33f1331a57bb0be0ccf585fa5d86f

Detection & response playbook

Credential / info stealer
  1. Find it

    Search your lockfiles and build artifacts for ranux-dev (version 5.0.0).

  2. If you installed it — respond

    ranux-dev is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If ranux-dev was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.

Frequently asked questions

No. ranux-dev on npm has been identified as a malicious package (version 5.0.0 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-018371

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks ranux-dev-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

ranux-dev (npm) malicious package — MAL-2026-14259 | O3 Security