Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

swiper-css-normalizenpm

Advisory published Updated

swiper-css-normalize is a confirmed malicious npm package (MAL-2026-7427) that runs destructive / sabotage code (malicious versions 1.0.3, 1.0.4, 1.0.5…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in swiper-css-normalize (npm)

MAL-2026-7427
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall swiper-css-normalize

Malicious versions

16 flagged
1.0.31.0.41.0.51.0.61.0.71.0.81.0.91.0.101.0.111.0.121.0.131.0.141.0.151.0.161.0.171.0.18

Indicators of compromise (SHA-256)

4cb924007b5712a1d9f45f0dbb620b29cb9e78dde85e8a7d928777537ea55d84
8649a5501ffc799a03bc766ddb6fe62584fde43df535bb27511eb5ddfd97d5d8

Detection & response playbook

Destructive / sabotage
  1. Find it

    Search your lockfiles and build artifacts for swiper-css-normalize (16 malicious versions).

  2. If you installed it — respond

    swiper-css-normalize carries a destructive/sabotage payload. Remove it immediately, restore any affected data from clean backups, and verify integrity of build outputs that may have been tampered with.

  3. Did it already run?

    If swiper-css-normalize was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.

Frequently asked questions

No. swiper-css-normalize on npm has been identified as a malicious package (versions 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.0.10, and 8 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

RLMA-2026-05327RLUA-2026-06515

References

Credits

  • ReversingLabs · finder

Detect & block this

O3 blocks swiper-css-normalize-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

swiper-css-normalize (npm) malicious package — MAL-2026-7427 | O3 Security