Malware in oem-agentic-shared
The npm package oem-agentic-shared contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
- Disclosed
- Last updated
- Blast radius
- Any system with the package installed or running
- Ecosystems
- Attack vectors
- Affected entities
- oem-agentic-sharednpm package containing malware
The npm package oem-agentic-shared has been identified as containing malware. According to the GitHub Advisory (GHSA-h957-h3mc-79qr), any computer that has this package installed or running should be considered fully compromised.\n\nThe advisory recommends that all secrets and keys stored on affected computers be rotated immediately from a different, uncompromised system. While the package should be removed, there is no guarantee that removal will eliminate all malicious software that may have been installed as a result of the initial compromise, given that the outside entity may have gained full control of the system.\n\nThis is classified as a critical-severity supply chain attack due to the complete system compromise potential and the broad impact on any system running the affected package.
Indicators of compromise
- Packages
- oem-agentic-shared
Remediation
- Immediately isolate any computer with oem-agentic-shared installed from the network
- Rotate all secrets, API keys, and credentials from a different, uncompromised computer
- Remove the oem-agentic-shared package from all systems
- Perform a full security audit and malware scan on affected systems
- Review system logs and network traffic for signs of unauthorized access or data exfiltration
- Consider full system reimaging if compromise is confirmed
Sources
- GitHub Advisory GHSA-h957-h3mc-79qr · GitHub Advisory Database
Cite this entry
"Malware in oem-agentic-shared." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 10, 2026; last updated July 10, 2026. https://supplychainattack.org/incident/malware-in-oem-agentic-shared-9cpk0s
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in @yancyyu/agentcli (npm)
The npm package @yancyyu/agentcli contains malicious code that extracts OAuth credentials and API keys for Lark/Feishu from the system keychain (macOS) and credential store (Windows), then exfiltrates them to a hardcoded remote IP address over plaintext HTTP. A persistent launchd agent ensures the exfiltration loop survives reboots.
npmAI agents & skillsCompromised packageMalicious commit - containedcritical
Malware in ai-sdk-helpers
The npm package ai-sdk-helpers was found to contain malware, potentially providing full system compromise to attackers. All affected systems should be considered fully compromised and all credentials rotated immediately from a clean machine.
npmAI agents & skillsCompromised package - containedcritical
Malware in openai-agents-helpers
The npm package openai-agents-helpers was found to contain malware. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmAI agents & skillsCompromised package - activecritical
Malware in ai-sdk-ollama
Malware discovered in the ai-sdk-ollama npm package. Systems with this package installed are considered fully compromised and require immediate remediation.
npmAI agents & skillsCompromised package