LWA-2026-12147 confirmed malware
strapi-plugin-rsh-meeb322k@3.6.8
Malicious code in strapi-plugin-rsh-meeb322k (npm)
T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1071 · Application Layer Protocol
Analysis
strapi-plugin-rsh-meeb322k@3.6.8 is a self-declared reverse-shell payload. Its package description reads "Reverse shell payload for Strapi", and its postinstall lifecycle hook executes postinstall.js (node postinstall.js) on install, running the payload on any machine that installs the package. The package was published under the name "strapi-plugin-rsh-meeb322k" and has since been removed from the registry; no further network IOCs were recoverable from the source.
- analyzed by
- Leitwacht
- first seen
- Sep 15, 2026, 06:48 AM
- analyzed
- Sep 15, 2026, 06:49 AM
Related advisories
- strapi-plugin-revsh-meeb322k@3.6.8
- strapi-plugin-revs-meeb322k@3.6.8
- strapi-plugin-rs-meeb322k@3.6.8
- n8n-nodes-healthmon@1.0.0
- tailwind-form-kit@0.6.2
- hydration-ui-pkg@1.0.0
- tailwindcss-3d-styles@1.2.2
- grafeno-webhook@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.