sbirontime@1.0.0
Malicious code in sbirontime (npm)
Analysis
The npm postinstall hook (elevated via UAC) installs a bundled VPN client and RDP Wrapper, then configures the host for covert remote access. It enables Remote Desktop on port 3389 with full shadow access without permission and Network Level Authentication disabled, creates or enables a local administrator account using a hardcoded password shipped in config.json, and registers a Windows service. It rewrites the PE version resources of the installed executables to masquerade as 'Service Host: Network Infrastructure Service' (svchost.exe) in Task Manager and Services, hides the installed folders and the created account from the sign-in screen, and stores the admin credentials in %ProgramData%\BikliWrapper\admin-credentials.json. No network C2 endpoint is used; access is via the enabled RDP listener and the hidden admin account.
- analyzed by
- Leitwacht
- first seen
- Aug 17, 2026, 04:14 AM
- analyzed
- Aug 17, 2026, 04:15 AM
Related advisories
- sbman@1.0.0
- @biklitime/biklimaster@1.1.6
- @diezyyasha/libsignal-node@2.2.8
- sbironman@1.0.0
- biklitool@1.1.11
- gpt-terminal-cli@1.0.0
- stellarfixer@1.0.0
- web3-token-helper@1.1.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.