Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

solidity-holdnpm

solidity-hold is a confirmed malicious npm package (MAL-2026-14220) that typosquats a legitimate package to trick installs (malicious version 2.0.1). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in solidity-hold (npm)

MAL-2026-14220
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall solidity-hold

What this malware does

The npm package [email protected] impersonates the popular pino logger: the README badges and lib/ source tree are copied from pino (pinojs/pino), but lib/config.js is replaced with a ~4 MB obfuscator.io-obfuscated bundle (hex string-array, rotating while(!![]) decoder IIFE, control-flow flattening, ~23,890-entry string array). index.js requires('./lib/config') at top level, so this opaque payload executes on any require('solidity-hold'). The advertised middleware export is a no-op stub, and the package declares an axios dependency (network egress capability) that a logger does not need. Publisher metadata (author Jackson Blau [email protected], bugs URL jsonspack.com/issues) is unrelated to the pino project whose code and branding are copied. Heavy control-flow obfuscation of an auto-executing module inside a package that impersonates a widely used dependency is a payload-carrier shape hostile to any installer that requires the module.

Malicious versions

1 flagged
2.0.1

Indicators of compromise (SHA-256)

39144e822a0964821b92859c04cbe7311ac13a889c585465ac0533c831f1904f

Detection & response playbook

Typosquat
  1. Find it

    Search your lockfiles and build artifacts for solidity-hold (version 2.0.1).

  2. If you installed it — respond

    solidity-hold is a typosquat — you almost certainly intended a legitimately-named package. Remove solidity-hold, install the correct package, and rotate any secrets exposed during the install since post-install scripts may have already run.

  3. Did it already run?

    If solidity-hold was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.

Frequently asked questions

No. solidity-hold on npm has been identified as a malicious package (version 2.0.1 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-018320

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks solidity-hold-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

solidity-hold (npm) malicious package — MAL-2026-14220 | O3 Security