app-hsu-layer@2.1.6
Malicious code in app-hsu-layer (npm)
Analysis
The postinstall hook executes a script that (1) recursively scans the working directory for credential/config files (id.json, config.toml, Config.toml, env, .env) and uploads each, prefixed with the OS username, to hxxp://95[.]216[.]118[.]146:3001/api/v1; and (2) fetches an SSH key and file-scan patterns from hxxp://170[.]205[.]31[.]203:3001/api/ssh-key, /api/scan-patterns and /api/block-patterns, then on Linux appends the attacker's SSH public key to ~/.ssh/authorized_keys and runs `sudo ufw enable` and `sudo ufw allow 22/tcp` to open SSH access, and finally scans the home directory (and Windows drives) for files matching the attacker-supplied patterns and batch-uploads them to hxxp://170[.]205[.]31[.]203:3001/api/v1. This installs a persistent SSH backdoor and exfiltrates local credential and configuration files to the two C2 hosts.
- analyzed by
- Leitwacht
- first seen
- Aug 5, 2026, 04:36 PM
- analyzed
- Aug 5, 2026, 04:38 PM
Related advisories
- nagixjs@2.1.6
- api-node-sdk@2.1.6
- api-rust-sdk@2.1.6
- app-svm-layer@2.1.6
- app-soda-layer@2.1.6
- app-sima-layer@2.1.6
- app-node-layer@2.1.6
- habingeer@2.1.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.