trimpromptnpm
trimprompt is a confirmed malicious npm package (MAL-2026-13462) that opens a backdoor for remote access (malicious versions 1.0.35, 1.0.42, 1.0.46…). Do not install it — remove it immediately and rotate any exposed credentials.
Malicious code in trimprompt (npm)
What this malware does
The package [email protected] ships a large set of heavily obfuscated JavaScript modules (hex-mangled identifiers _0x... across cache-manager.js, cache.js, ccr.js, dashboard.js, executor.js, file-watcher.js, hooks/claude-hook.js, mcp.js, proxy-conv.js, proxy-resp.js, redactor.js, seed.js, simulate.js, sync.js, tracker.js, and all filters/*.js) whose original structure and destinations are deliberately hidden. Two of these obfuscated files (sync.js and tracker.js) additionally combine require('child_process') with HTTP POST calls carrying host/identifier fields — the shape of host-reconnaissance and outbound reporting to a remote endpoint. A postinstall.js script auto-executes on npm install and spawns PowerShell (spawn('powershell',...)), and shims.js also invokes child_process and runs execSync('pwsh...'), providing an install-time and load-time execution surface on Windows hosts. The combination of pervasive identifier-level obfuscation across nearly every module, a PowerShell-spawning postinstall lifecycle hook, and obfuscated modules that pair child_process with HTTP POST of host identifiers is inconsistent with a legitimate prompt-trimming utility and matches the shape of an install-time execution + host-beaconing supply-chain payload. Concrete destination hostnames/URLs are hidden behind the string-array obfuscation and are not recoverable from identifier evidence alone.
Malicious versions
Indicators of compromise (SHA-256)
Detection & response playbook
Backdoor / remote accessFind it
Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for trimprompt (6 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging trimprompt across your stack and pipelines.
If you installed it — respond
trimprompt establishes remote access, so treat any host that installed it as fully compromised. Isolate the machine, remove the package, rotate all credentials it could reach, and rebuild from a trusted image rather than cleaning in place — a backdoor may have planted additional persistence.
Did it already run?
If trimprompt was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.
How O3 protects you
O3 blocks trimprompt before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.
Frequently asked questions
Campaign
References
Credits
- Amazon Inspector · finder
Detect & block this
O3 blocks trimprompt-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the C2 callback and severs the channel.