cbc97b7a@1.1787999998.0
Malicious code in cbc97b7a (npm)
Analysis
The package's description field contains a base64-encoded shell script that deploys a Monero (XMRIG) cryptominer. On execution the script kills competing miner processes (syslog-ng, donat-level, stratum+tcp, cryptonight, randomx, kill_cryptojack, high-CPU processes), scrubs crontab entries and adds iptables DROP rules for known miner C2 IPs (95[.]85[.]237[.]226, 193[.]41[.]68[.]194, 95[.]85[.]237[.]149, 2[.]26[.]99[.]68, 210[.]195[.]19[.]39, 66[.]23[.]199[.]44, 45[.]94[.]31[.]89, 139[.]59[.]59[.]33, 154[.]89[.]152[.]115, 84[.]21[.]173[.]223, 142[.]132[.]131[.]238), patches /lib/systemd/cache/process-watcher to run xmrig with the attacker's pool wallet 883kAB7UfoJCKPzZAavUCHJdH4L2qVjqw4A79diUrFjBWBFrerhXP FbbUZnY2CemcUiBcLpAUz38vVYBbUqTHAgoAwgBCFH, replaces the pool user in /var/tmp/.odoo_pg_health.json, removes competing miner artifacts, and fetches a miner config from hxxps://github[.]com/alsat/config[.]json.
- analyzed by
- Leitwacht
- first seen
- Aug 29, 2026, 11:46 AM
- analyzed
- Aug 29, 2026, 11:48 AM
Related advisories
- mutex-thread@1.3.0
- osinthell@1.9.5
- super-test-json@1.2.0
- sbman@1.0.0
- sbironman@1.0.0
- wormgpt-cli@1.0.1
- delta-time-32bb@1.0.0
- fb-cards-form-no-resident-information@20.4.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.