runtimekitnpm
runtimekit is a confirmed malicious npm package (MAL-2026-6477) that executes malicious code on install (malicious versions 1.0.1, 1.0.5). Do not install it — remove it immediately and rotate any exposed credentials.
Malicious code in runtimekit (npm)
What this malware does
lib/index.cjs and lib/index.mjs (re-required from lib/readonly.cjs) contain a self-executing IIFE that decodes two opaque strings via a custom shuffle routine (YWG), recovers the identifier constructor from one of them, retrieves the Function constructor via property access, then builds and invokes nested Function-constructor calls — Function('', Function('', decoded1))(decoded2)(7942) — executing arbitrary decoded JavaScript at module load. Before the synthesis, the loader assigns global.r = require and global.m = module, deliberately smuggling Node's require and module bindings into the global scope so the dynamically constructed function (which does not inherit the module's closure) can reach them. A marker global._V = "A6-Shadow-16" is also set. The package advertises itself as a validation/runtime utility but ships an obfuscated self-injecting loader with no legitimate purpose for hiding code from Function constructors. Any consumer that does require('runtimekit') or require('runtimekit/readonly') runs the decoded payload in-process with full Node privileges.
Malicious versions
Indicators of compromise (SHA-256)
Detection & response playbook
Malicious packageFind it
Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for runtimekit (2 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging runtimekit across your stack and pipelines.
If you installed it — respond
Remove runtimekit from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.
Did it already run?
If runtimekit was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.
How O3 protects you
O3 blocks runtimekit before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.
Frequently asked questions
Campaign
References
Credits
- Amazon Inspector · finder
Detect & block this
O3 blocks runtimekit-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.