Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

remove-bg-serverless-azurenpm

Advisory published Updated

remove-bg-serverless-azure is a confirmed malicious npm package (MAL-2026-14438) that executes malicious code on install (malicious versions 1.0.1, 1.1.1). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in remove-bg-serverless-azure (npm)

MAL-2026-14438
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall remove-bg-serverless-azure

What this malware does

package.json declares preinstall: node index.js, so npm install automatically runs index.js. index.js reads os.hostname(), os.userInfo(), the user home directory, DNS server configuration, and the contents of /etc/passwd and /etc/hosts, and POSTs the collected data over HTTPS to the hardcoded host 7iqn7pls4ly6w8valba0xcxygpmha7yw.oastify.com (a Burp Collaborator / OAST subdomain used as an attacker-controlled callback). Installing the package causes installer-side identifiers and sensitive system files to be sent to an external attacker endpoint on install.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

2 flagged
1.0.11.1.1

Indicators of compromise (SHA-256)

dcbce8344eb0762c4a9ef029743efe13045422b839444b828c245a09a85fc74e
038ed421b0adefaa811442ca01d52f8cdc5003752e40d901464f8d9ccce8a8fa
5a311c3bc5df7907a41d7c257f62ffdaa663fb31d6d5ee40e6da536f0110c1f4

Detection & response playbook

Malicious package
  1. Find it

    Search your lockfiles and build artifacts for remove-bg-serverless-azure (2 malicious versions).

  2. If you installed it — respond

    Remove remove-bg-serverless-azure from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If remove-bg-serverless-azure was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.

Frequently asked questions

No. remove-bg-serverless-azure on npm has been identified as a malicious package (versions 1.0.1, 1.1.1 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-018641GHSA-65rf-pp5h-8fw9IN-MAL-2026-019796

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks remove-bg-serverless-azure-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

remove-bg-serverless-azure (npm) malicious package — MAL-2026-14438 | O3 Security