Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

resolve-auditnpm

resolve-audit is a confirmed malicious npm package (MAL-2026-13987) that executes malicious code on install (malicious version 99.9.1). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in resolve-audit (npm)

MAL-2026-13987
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall resolve-audit

What this malware does

[email protected] is a stub package (index exports an empty object) whose package.json declares its only dependency ltidisafe as a direct HTTPS tarball URL: https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.6.6.tgz. On npm install, npm fetches this arbitrary tarball from an anonymous, mutable Google Cloud Storage bucket (path segment depenconf, a dependency-confusion marker) rather than resolving through the npm registry, with no version-by-hash pinning. Any lifecycle scripts inside that tarball execute on the installer. The version number 99.9.1 is characteristic of dependency-confusion/version-squat lures designed to win resolution against a private-registry package of the same name.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

1 flagged
99.9.1

Indicators of compromise (SHA-256)

86b902b4dc4c2187bb95548ed903dfea70ea626ba5450f031c2cb27b3639dd1c
58ff2b4a4d1fb90a19c0d2673633f06ecc737fd284d08676fadb90bef8b3cf9c

Detection & response playbook

Malicious package
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for resolve-audit (version 99.9.1). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging resolve-audit across your stack and pipelines.

  2. If you installed it — respond

    Remove resolve-audit from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If resolve-audit was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks resolve-audit before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. resolve-audit on npm has been identified as a malicious package (version 99.9.1 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-017677GHSA-69qf-g8jq-47xv

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks resolve-audit-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

resolve-audit (npm) malicious package — MAL-2026-13987 | O3 Security