Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

snavboxnpm

snavbox is a confirmed malicious npm package (MAL-2025-49362) that executes malicious code on install (malicious versions 1.0.0, 1.0.2, 1.0.3). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in snavbox (npm)

MAL-2025-49362
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall snavbox

What this malware does

At CLI startup, index.js downloads three native shared libraries (sbx.so, bot.so, v1.so) from https://${arch}.31888.xyz/ (amd64.31888.xyz, arm64.31888.xyz), writes them to disk, and loads them via koffi.load() to invoke native functions from the fetched bytes. The download URL is not version-pinned, the domain is unrelated to the package publisher, and the downloadLibrary(url, fileName, expectedSha256) helper treats an empty expectedSha256 as a pass, so no integrity check is performed. Package metadata describes the project as "WildGuard - Protect Our Wildlife" with an accompanying wildlife-themed index.html, but the actual code implements a sing-box multi-protocol proxy (vless/vmess/trojan/hysteria2/tuic/reality/anytls), a Cloudflare Argo tunnel configured with noTLSVerify: true, a Nezha remote-management agent, and a hardcoded keep-alive callback to https://keep.gvrander.eu.org/add-url. Multiple execSync('curl...') invocations are also present. The mismatch between the advertised purpose and the shipped behavior, combined with the unpinned unverified native-code fetch from a non-publisher host, gives the operator of 31888.xyz arbitrary code execution on any host that runs this package.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

The OpenSSF Package Analysis project identified 'snavbox' @ 1.0.0 (npm) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.

Malicious versions

3 flagged
1.0.01.0.21.0.3

Indicators of compromise (SHA-256)

d8c70660a97aff07d3f4c6a0c03af63cceb7fcefdd52b293ef98b0be0ae55df8
d5b800cf1343124b2025857e06735a74edfe8d473a828b7d2fe2df88c1e76df5
4b16f46f7bce0e06e8afe06d96ba465799db8e470814384124b318b2b98285ff
b5af4f54b61e8c07cb80d8f65c7ff554627597f600fe3b67094eb71097903548
d0fcbd177b5fa8589dc78355b7a674f00be77d2e7574198be244c1ee94b678bc

Detection & response playbook

Malicious package
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for snavbox (3 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging snavbox across your stack and pipelines.

  2. If you installed it — respond

    Remove snavbox from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If snavbox was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks snavbox before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. snavbox on npm has been identified as a malicious package (versions 1.0.0, 1.0.2, 1.0.3 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

GHSA-ppfj-vpcr-qwqgIN-MAL-2026-017979IN-MAL-2026-018586

References

Credits

  • Amazon Inspector · finder
  • OpenSSF: Package Analysis · finder

Detect & block this

O3 blocks snavbox-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

snavbox (npm) malicious package — MAL-2025-49362 | O3 Security