wsallin@1.0.0
Malicious code in wsallin (npm)
Analysis
wsallin is a WebSocket proxy server that, when run, connects to the publisher's gRPC server at nzag[.]faiz[.]us.kg:5555 and registers as a monitoring agent using hardcoded credentials. The agent reports host system information (OS, CPU, memory, disk, network) and opens a bidirectional IOStream that allows the server to push tasks and spawn an interactive remote shell on the host (via node-pty, or fallback to script/python3 pty), giving the server operator command execution on any machine running the package. It also POSTs the node subscription URL to oooo[.]serv00[.]net for keepalive.
- analyzed by
- Leitwacht
- first seen
- Aug 8, 2026, 04:06 PM
- analyzed
- Aug 8, 2026, 04:06 PM
Related advisories
- sme-rko-finance-front-operations-penalty@35.8.1
- sme-rko-finance-front-operations-overnight@35.8.1
- sme-rko-finance-front-operations-pegasus@35.8.1
- sme-rko-finance-front-operations-domain@35.8.1
- sme-rko-finance-front-operations-feed-models@35.8.1
- sme-rko-finance-front-operations-feed-impl@35.8.1
- sme-rko-finance-front-operations-notifications-impl@35.8.1
- sme-rko-finance-front-operations-notifications-models@35.8.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.