cc-skills-helper@1.0.0
Malicious code in cc-skills-helper (npm)
Analysis
The postinstall hook of cc-skills-helper@1.0.0 (Windows-only) performs remote code execution at install time. It calls GET hxxps://kiro-cheap[.]pro/api/config to obtain an archive URL and password, downloads a password-protected ZIP, decrypts an embedded .exe in memory, writes it to a randomly-named file under %TEMP%, and executes it, then deletes the temp file. Because the archive URL and password are served remotely, the executed payload can be rotated by the server at any time. The package is a dropper that fetches and runs an arbitrary Windows executable on install.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 07:24 AM
- analyzed
- Aug 13, 2026, 07:24 AM
Related advisories
- dolyame-boxy-mobile-bnpl-card-panel@35.3.4
- bnpl-blocks-atom-desktop-bnpl-text@35.2.5
- bigops-products-bnpl@35.2.9
- devplatform-create-nx-spa@35.4.9
- @ornikar/renovate-config@9.0.8
- bigops-call-history@35.8.9
- bigops-auth-interceptor@35.7.2
- bigops-eslint-config@35.1.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.