Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

the_tax_free_cashier_is_at_9fnpm

Advisory published Updated

the_tax_free_cashier_is_at_9f is a confirmed malicious npm package (MAL-2026-14549) that executes malicious code on install (malicious versions 1995.3.2-0.miasma, 1995.3.20, 2026.6.2-5.hades.no.isshouni…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in the_tax_free_cashier_is_at_9f (npm)

MAL-2026-14549
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall the_tax_free_cashier_is_at_9f

What this malware does

The package was found to contain malicious code or consuming dependency that contains malicious code

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

4 flagged
1995.3.2-0.miasma1995.3.202026.6.2-5.hades.no.isshouni2026.6.3-0.hades.no.isshouni

Indicators of compromise (SHA-256)

6cd5486908280c6ffff3c0177af75fcd17d2ce470c45862b81d6ac4c66193308
0596e225c3ec8b9dfbd5c47b4c4c02d5f5f15c1aff917e7ab480c21936184164
0806e6fe11e8fd9ea4c5e8e1e0570b520be5d9f89b8577eed33fb26658dbff7f
4a086db16edcd703d6c9883f88572d6f863795ae7ed3ffbd6114ee2cff9546df
d0950a61c26d55e1bfb851cc79890aedc4333b90e9adb97e725c01da20c060cd

Detection & response playbook

Malicious package
  1. Find it

    Search your lockfiles and build artifacts for the_tax_free_cashier_is_at_9f (4 malicious versions).

  2. If you installed it — respond

    Remove the_tax_free_cashier_is_at_9f from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If the_tax_free_cashier_is_at_9f was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.

Frequently asked questions

No. the_tax_free_cashier_is_at_9f on npm has been identified as a malicious package (versions 1995.3.2-0.miasma, 1995.3.20, 2026.6.2-5.hades.no.isshouni, 2026.6.3-0.hades.no.isshouni flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

GHSA-4hc4-fpvc-7chpIN-MAL-2026-019206IN-MAL-2026-019208IN-MAL-2026-019207IN-MAL-2026-019205

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks the_tax_free_cashier_is_at_9f-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

the_tax_free_cashier_is_at_9f (npm) malicious package — MAL-2026-14549 | O3 Security