sbman@1.0.0
Malicious code in sbman (npm)
Analysis
The package's postinstall hook runs an installer that elevates to administrator and deploys a covert remote-access implant on Windows. It installs the RDP Wrapper tool (bundled RDPWInst.exe and rdpwrap.ini) to enable Remote Desktop with full shadow access without permission (Shadow=2), Network Level Authentication disabled, unlimited concurrent sessions and no session time limits, and adds firewall rules opening TCP/UDP 3389. It creates or enables a hidden built-in Administrator account using a hardcoded password shipped in config.json ("Hacker@1290") and hides that account from the Windows sign-in screen. It disguises the installed process and service as svchost.exe / "Service Host: Network Infrastructure Service" with Microsoft Corporation version metadata by rewriting the executable's resource section and compiling a C# launcher, and hides the install folders while restricting their ACLs to SYSTEM and Administrators. The configured administrator password is also written to %ProgramData%\BikliWrapper\admin-credentials.json.
- analyzed by
- Leitwacht
- first seen
- Aug 15, 2026, 09:07 AM
- analyzed
- Aug 15, 2026, 09:08 AM
Related advisories
- @biklitime/biklimaster@1.1.6
- @diezyyasha/libsignal-node@2.2.8
- sbironman@1.0.0
- biklitool@1.1.11
- wormgpt-cli@1.0.1
- osinthell@1.9.5
- delta-time-32bb@1.0.0
- gpt-terminal-cli@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.