OpenSSF/OSV advisory MAL-2026-4542 confirms this npm version as malicious. Package name typosquats the widely-used crypto-js library and mirrors its API surface, README, and repository references to appear legitimate. package.json declares `"preinstall": "./.claude/set"`, where `.claude/set` is a 5,092,012-byte Linux ELF binary explicitly included in the published `files` array. Running `npm install crypto-javascript` executes this opaque native binary with the installer's privileges...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in crypto-javascript (npm)
Details
Package name typosquats the widely-used crypto-js library and mirrors its API surface, README, and repository references to appear legitimate. package.json declares `"preinstall": "./.claude/set"`, where `.claude/set` is a 5,092,012-byte Linux ELF binary explicitly included in the published `files` array. Running `npm install crypto-javascript` executes this opaque native binary with the installer's privileges. A second auto-execution vector is configured in `.claude/settings.json`, which registers a Claude Code `SessionStart` hook with matcher `*` that runs the same `./set` binary whenever a developer opens the project directory in Claude Code — this persists even if the installer uses `npm install --ignore-scripts`. Strings extracted from the binary include a hardcoded IPv4 endpoint `207.90.194.2:44...` adjacent to TLS handshake symbols (`EVP_PKE`, `X509_CTX`, `TLS`, `RSA_PKCS1_SHA384`) and `BZ2_bzDecomp` imports indicating a packed/compressed payload — the structural shape of a TLS-based C2 dropper. The binary's purpose is undocumented and unrelated to the package's advertised cryptographic-library function.
## Source: google-open-source-security (d83c3b506a10b770a8c1f98d280262478cccc65708bb1066a72e0708dccaaf75) This malicious package is part the IronWorm campaign. This campaign executes a malicious binary payload during installation via a preinstall hook. The payload is a Rust-built infostealer that targets developer environments, scanning for and harvesting credentials related to cloud providers, object storage, databases, source-control, package registries, and AI developer tools. It also targets cryptocurrency wallets, specifically injecting a malicious JavaScript hook into the Exodus desktop wallet to capture passwords and recovery phrases. Furthermore, the malware exhibits worm-like behavior by stealing GitHub and NPM credentials to push malicious updates to the victim's repositories and publish trojanized packages, and it uses an eBPF-based kernel rootkit to hide its processes and network connections on Linux systems.