@biklitime/biklimaster@1.1.6
Malicious code in @biklitime/biklimaster (npm)
Analysis
On install, this Windows-only package silently enables Remote Desktop on port 3389, installs the third-party RDP Wrapper tool to patch termsrv.dll, and creates or enables a hidden local administrator account (the built-in Administrator, or a new 'admin'/'user' account) using a hardcoded password shipped in the package's config.json. The account is added to the Administrators and Remote Desktop Users groups, hidden from the Windows sign-in screen, and its credentials are written to %ProgramData%\BikliWrapper\admin-credentials.json. Network Level Authentication is disabled and firewall rules are opened for port 3389. The result is persistent remote RDP access to the machine with a known password.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 02:56 AM
- analyzed
- Aug 13, 2026, 02:57 AM
Related advisories
- biklitool@1.1.11
- sbirontime@1.0.0
- sbman@1.0.0
- sbironman@1.0.0
- @diezyyasha/libsignal-node@2.2.8
- @kentsuki/baileys@1.0.0
- tron-toolkit@1.0.1
- gpt-terminal-cli@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.