Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

zer0onedatetoolnpm

Malicious code in zer0onedatetool (npm) Remove it immediately and rotate any exposed credentials.

MAL-2026-5536
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall zer0onedatetool

What this malware does

The postinstall lifecycle script in this package issues curl POST requests to a subdomain of oastify.com — the out-of-band callback domain operated by Burp Collaborator / Project Discovery's interactsh. On every npm install, the script triggers an outbound HTTP request to an attacker-controlled OOB endpoint, which is the canonical fingerprint of a dependency-confusion / supply-chain reconnaissance payload (verifying the package landed in a victim environment and beaconing identifying host information out). The destination is not associated with any legitimate package functionality. Installer impact: any machine running npm install on this package automatically beacons to the attacker's OOB collector, leaking install-time host metadata and confirming code execution to the attacker.

Malicious versions

1 flagged
1.0.0

Indicators of compromise (SHA-256)

73fd05fda74bbf13c6275d4da0fa80fece821cad03fb2237ae74ed24309eab52

Frequently asked questions

No. zer0onedatetool on npm has been identified as a malicious package (version 1.0.0 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-005327

References

Credits

  • Amazon Inspector · finder

Scan your dependencies

O3 Security blocks malicious packages like this at install time and in CI.

Supply-chain protection
zer0onedatetool (npm) malicious package — MAL-2026-5536 | O3 Security