Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

rsflows-pexmlnpm

Malicious code in rsflows-pexml (npm) Remove it immediately and rotate any exposed credentials.

MAL-2026-3422
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall rsflows-pexml

What this malware does

The package rsflows-pexml was found to contain malicious code.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

The OpenSSF Package Analysis project identified 'rsflows-pexml' @ 99.9.25 (npm) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.

Malicious versions

2 flagged
99.9.999.9.25

Indicators of compromise (SHA-256)

144a8e247e6bb6c7b08119900b2d70af4ee7a594650d03adb2fbf731963e521d
ca8cde633391c1292f4bc8a50e783760044b5bea6312639fb3470418619c1b9d
4ef5b11ec067e18cc3a024fee21e569e0f44cf180619e974cbb1dd8325e1b10c
f1f4ac6cd17db4404613301b8405f7033d584985cb52af8c0aee3042bc1c0c8d

Frequently asked questions

No. rsflows-pexml on npm has been identified as a malicious package (versions 99.9.9, 99.9.25 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

GHSA-m2qp-j4c5-7m6m

References

Credits

  • Amazon Inspector · finder
  • OpenSSF: Package Analysis · finder

Scan your dependencies

O3 Security blocks malicious packages like this at install time and in CI.

Supply-chain protection
rsflows-pexml (npm) malicious package — MAL-2026-3422 | O3 Security