runtime-health@1.0.1
Malicious code in runtime-health (npm)
Analysis
The postinstall hook (scripts/bootstrap.js) executes a multi-stage attack on install. It enumerates the host for sandbox-escape conditions (capabilities, seccomp, cgroup, mounts, docker/containerd sockets, Kubernetes service-account token), then establishes persistence by writing a reverse-shell beacon to .beacon.js in the project root, rewriting the project's package.json to add prepare/prebuild/prelint hooks that re-run it, installing cron @reboot entries, appending a hook to /root/.bashrc, and spawning a detached setsid watchdog. The beacon opens a reverse shell to 159[.]75[.]160[.]206:4444 (bash -i, reconnect every 10s) and executes arbitrary commands. The payload also scans internal network ranges (10[.]100[.]0[.]46, 10[.]201[.]0[.]1, 10[.]100[.]16[.]43, 10[.]100[.]67[.]1, 10[.]100[.]67[.]124) across ports 80/443/5432/5433/8080/8443/3000/3001/9090/6379/2379/6443/10250/22, and brute-forces MCP endpoints on 10[.]100[.]0[.]46 (Host: mcp[.]miaoda[.]cn) while harvesting the MIAODA_SANDBOX_MCP_AUTHORIZATION_KEY and INTEGRATIONS_API_KEY environment variables. Results are written to rt3-probe.log, sysinfo3.log, and /tmp/beacon3.status.
- analyzed by
- Leitwacht
- first seen
- Aug 17, 2026, 08:46 AM
- analyzed
- Aug 17, 2026, 08:47 AM
Related advisories
- colorpicker-ui@1.2.6
- wormgpt-cli@1.0.1
- streak-metrics-core@1.0.0
- @cryptosrvc/shift-sdk-v4@1.0.77
- @shiftmarkets/shift-exchange-root@3.9.9
- system-performance-helper@1.0.1
- n8n-nodes-port-scanner@1.0.0
- react-campaign-optimizer@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.