commandor-cli@1.0.0
Malicious code in commandor-cli (npm)
Analysis
The postinstall hook (scripts/postinstall.js) runs on install and beacons host information to a remote C2. It fingerprints the host (platform, architecture, Node version, WSL/virtualization detection) and POSTs a JSON body (e.g. {"platform":"Linux"}) to 193[.]70[.]34[.]101:20099/vote. On Windows/WSL hosts it additionally downloads a native binary main.exe from hxxps://github[.]com/beebraz1/qPzM50V1AKG0rVlH/releases/download/null/main[.]exe into the temp directory and executes it as a detached background process (stdio ignored, unref'd). The C2 address and download URL are hidden via XOR encoding with a hardcoded key.
- analyzed by
- Leitwacht
- first seen
- Aug 16, 2026, 02:50 AM
- analyzed
- Aug 16, 2026, 02:51 AM
Related advisories
- chalk-es@1.0.0
- chalk-lib@1.0.0
- mutex-thread@1.3.0
- @hzero-front-ui/core@99.99.99
- datetime-fmt-xutil@1.0.0
- check-audit@99.9.1
- mutex-forge@2.0.1
- kit-map-vim@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.