Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

reactive-cdk-appnpm

Malicious code in reactive-cdk-app (npm) Remove it immediately and rotate any exposed credentials.

MAL-2026-4254
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall reactive-cdk-app

What this malware does

package.json declares preinstall: node index.js, so installation automatically executes index.js. The script reads /etc/passwd via fs.readFileSync, collects hostname, username, platform, cwd, and home directory from the os module, slices the first 30 entries of process.env (which on CI typically include AWS_*, GITHUB_TOKEN, NPM_TOKEN, and similar credentials), and HTTPS-POSTs the JSON payload to 3nrgzlqwix6erldow0s0kttsojuai36s.oastify.com — a Burp Collaborator out-of-band exfiltration subdomain. The package name and description ('package of the reactive-cdk-app of the aws') impersonate AWS CDK naming, fitting a typosquat-with-payload pattern. Any developer or CI system running npm install reactive-cdk-app leaks host identity, the local user database, and a bulk slice of environment secrets to the attacker.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

The OpenSSF Package Analysis project identified 'reactive-cdk-app' @ 1.0.1 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

Malicious versions

4 flagged
1.0.11.0.21.0.31.0.4

Indicators of compromise (SHA-256)

d01657e9ca5ae8e8f34576437bbc86bb276c83d99dfd1563da57fe880a6ac6fd
ad185c182eb6262541352d633509ab6c3b35e66e0456b9a6871da0641a4ad1b1
ca92f78b93f86679498366c041a15bbfa55e8a2f9d14d0263c876aea75cefe27
d07f0097c4a9b1169ba7069a197de2fb3770ba5d3e5904af463c750e226a2c7c
062b4ae8e07104f0c7a05845432701b2927c63f3a678b27108db6837eca35443
2ee2278b633f78383f38f7b885af48b8346d4291b8eada608a94024b39080358
495d1f7b248c12ccb1f7d7dbc1f97f0462f21bb13d6a7c2639e280efc97bf2d9
84d7572f96294e867b18a0448ac0e70af3d08769749aa73388b38d88492559e4
171cafb2d7e5b500dd92fe5d46da3a09b37ac9ff62af885241b41e8401746144

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for reactive-cdk-app (4 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging reactive-cdk-app across your stack and pipelines.

  2. If you installed it — respond

    reactive-cdk-app is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If reactive-cdk-app was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks reactive-cdk-app before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. reactive-cdk-app on npm has been identified as a malicious package (versions 1.0.1, 1.0.2, 1.0.3, 1.0.4 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-004191IN-MAL-2026-004185IN-MAL-2026-004178IN-MAL-2026-004179IN-MAL-2026-004180IN-MAL-2026-004186IN-MAL-2026-004190GHSA-ppjp-2h29-66pv

References

Credits

  • Amazon Inspector · finder
  • OpenSSF: Package Analysis · finder

Detect & block this

O3 blocks reactive-cdk-app-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

reactive-cdk-app (npm) malicious package — MAL-2026-4254 | O3 Security