Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

vue-demi-fixnpm

vue-demi-fix is a confirmed malicious npm package (MAL-2026-6702) that steals credentials and exfiltrates sensitive data (malicious versions 10.0.0, 10.0.1, 10.0.2…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in vue-demi-fix (npm)

MAL-2026-6702
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall vue-demi-fix

What this malware does

vue-demi-fix is a name-confusion package against the widely used vue-demi library. package.json declares both preinstall and postinstall lifecycle scripts that invoke curl against a hardcoded bare-IP HTTP endpoint (http://109.71.252.153:8080/), exfiltrating the installer's OS, username (whoami), current working directory (pwd), and hostname as URL query parameters on every npm install. The package ships no real functionality — index.js only prints a proof-of-concept notice and README self-labels as a 'Responsible Disclosure' PoC. Regardless of the PoC framing, installers receive no benign function and their host identity is unconditionally beaconed to a non-publisher, non-registry endpoint on a default install.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

The OpenSSF Package Analysis project identified 'vue-demi-fix' @ 10.0.4 (npm) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.

Malicious versions

7 flagged
10.0.010.0.110.0.210.0.310.0.410.0.510.0.6

Indicators of compromise (SHA-256)

8fd5381cd4364444dac8d64b33e317c526ef52948ebfb9d10e11ec0909b7d383
3bf683b6e8715fecd451a06da256d90048054cbe463da64e43c1a8db4226b661
41d430d87db19b144ee6213294cc5dd634b60288db5dd1c9ba6d57e23d90140c
de927f8bd731d104d0cd6444386a8c9a050331d85b1de57a14bee2c7f4baa0e7
d7b22421b823a36a6fb2fd7e87fa26c411df120bbfa7d84514b0099c9ba5c804
1b1a6b5f0bfde23791de164bf5a33eef95035ab7ebda5beba25d77d3efa41f14
6f6e47edd6c9a1a932087f349f9355883a68d49677678fa2aede48fc4997507b
7ece3015c35f384a55df7a138a80f11b4fe3bc01e4b7c87812a9e3e7112fbd48
f4e0ece38391bdd664130c49b929c1bcfa74baf7f147a95dbea030c5e517d8d4

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for vue-demi-fix (7 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging vue-demi-fix across your stack and pipelines.

  2. If you installed it — respond

    vue-demi-fix is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If vue-demi-fix was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks vue-demi-fix before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. vue-demi-fix on npm has been identified as a malicious package (versions 10.0.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4, 10.0.5, 10.0.6 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-007842IN-MAL-2026-007844IN-MAL-2026-007843GHSA-p53q-mf26-4h26IN-MAL-2026-012931IN-MAL-2026-012958IN-MAL-2026-012930IN-MAL-2026-012956

References

Credits

  • Amazon Inspector · finder
  • OpenSSF: Package Analysis · finder

Detect & block this

O3 blocks vue-demi-fix-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

vue-demi-fix (npm) malicious package — MAL-2026-6702 | O3 Security