@biklitime/biklimaster@1.1.6
Malicious code in @biklitime/biklimaster (npm)
Analysis
On install, this Windows-only package silently enables Remote Desktop on port 3389, installs the third-party RDP Wrapper tool to patch termsrv.dll, and creates or enables a hidden local administrator account (the built-in Administrator, or a new 'admin'/'user' account) using a hardcoded password shipped in the package's config.json. The account is added to the Administrators and Remote Desktop Users groups, hidden from the Windows sign-in screen, and its credentials are written to %ProgramData%\BikliWrapper\admin-credentials.json. Network Level Authentication is disabled and firewall rules are opened for port 3389. The result is persistent remote RDP access to the machine with a known password.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 02:56 AM
- analyzed
- Aug 13, 2026, 02:57 AM
Related advisories
- @diezyyasha/libsignal-node@2.2.8
- gpt-terminal-cli@1.0.0
- stellarfixer@1.0.0
- web3-token-helper@1.1.3
- xeiko-cdn@1.0.0
- @rblxts/services@1.6.0
- @solana-js/web3@1.91.3
- @coralxyz/anchor@0.30.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.