Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

ts-webplugnpm

ts-webplug is a confirmed malicious npm package (MAL-2026-5994) that opens a backdoor for remote access (malicious versions 3.0.5, 3.0.6, 3.0.7…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in ts-webplug (npm)

MAL-2026-5994
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall ts-webplug

What this malware does

The package impersonates the pino logger (README titled 'chai-mocks', badges linking to pinojs/pino, module export named pino) while its actual package name ts-webplug is unrelated. When a consumer requires the package and invokes its exported middleware, index.js spawns lib/caller.js as a detached Node child process. lib/caller.js performs axios.get(...) against https://jsonhosting.com/api/json/9343c2ce/raw, extracts the cookie field from the response, and passes it to new Function.constructor('require', s)(require) — evaluating attacker-controlled JavaScript with full require access in the consumer's Node process. The remote URL is additionally concealed in a spoofed process.env object where DEV_API_KEY is a base64 blob decoding to a jsonkeeper.com URL (a second mutable, anonymous-host pointer in lib/const.js decodes to https://jsonkeeper.com/b/4NAKK). The fetch host is a mutable anonymous paste service — today's payload can be swapped for anything at any time — and the executed code runs with full Node privileges on the installer/consumer machine.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

4 flagged
3.0.53.0.63.0.73.0.8

Indicators of compromise (SHA-256)

2a205cee3f545c9dd5083055f8dad50c5e131603bf50d37bbb3f7ef5a744d88f
ab49780fe41f3794685e5956a0d5a7c3ecdf35303b839d14f2b2d6c11d20032e
4097a5eb4f12223bba1d71dc7e04f525df3dae72db5911d46bc988f289eb9351
6b45f0926ced2cc9a58cf059d69dfdfe0f5e2d0c772aa25d350b6088f57d5056
a120eb8e3f6ca34493b7f282544523ab60137e8388148b191f46cda094e50789
cdc68525efe47411d3ce86b63014de43219fb1ea48e7d703a7db716e41b7de86

Detection & response playbook

Backdoor / remote access
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for ts-webplug (4 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging ts-webplug across your stack and pipelines.

  2. If you installed it — respond

    ts-webplug establishes remote access, so treat any host that installed it as fully compromised. Isolate the machine, remove the package, rotate all credentials it could reach, and rebuild from a trusted image rather than cleaning in place — a backdoor may have planted additional persistence.

  3. Did it already run?

    If ts-webplug was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks ts-webplug before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. ts-webplug on npm has been identified as a malicious package (versions 3.0.5, 3.0.6, 3.0.7, 3.0.8 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-006883GHSA-m637-4v9j-499pIN-MAL-2026-009192IN-MAL-2026-009191IN-MAL-2026-009193

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks ts-webplug-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the C2 callback and severs the channel.

Explore

ts-webplug (npm) malicious package — MAL-2026-5994 | O3 Security