@asenfotech/unplugin-element-plus@2.9.3
Malicious code in @asenfotech/unplugin-element-plus (npm)
Analysis
The postinstall hook (postinstall-run.cjs -> tooling-bootstrap.cjs) runs a base64-encoded remote-access agent. On install it registers the host with the C2 server at hxxps://npmjs[.]it[.]com/ (a typosquat of npmjs[.]com) via POST /api/register, sending hostname, username, and OS. It then polls GET /api/task/{agent_id} for commands and executes arbitrary shell commands on the victim machine via cmd.exe /c or /bin/sh -c, uploading command output to /api/result/{agent_id} and file contents to /api/file/{agent_id}/{task_id}. The agent only activates when the consumer project contains specific sentinel files (src/pages/GameAggregator/GameAggrBusinessPage/index.tsx, src/router/RouterProvider.tsx, src/api-gs/dictionaries.ts), indicating a targeted attack. The package's main index.js is a decoy Element Plus resolver.
- analyzed by
- Leitwacht
- first seen
- Sep 16, 2026, 08:50 AM
- analyzed
- Sep 16, 2026, 08:51 AM
Related advisories
- strapi-plugin-perev-meeb@3.6.8
- strapi-plugin-pysh-meeb@3.6.8
- strapi-plugin-ccip-meeb@3.6.8
- strapi-plugin-conresh-meeb@3.6.8
- strapi-plugin-cccon-meeb@3.6.8
- swnwall@1.2.10
- engin1@1.3.99
- tol8t@14.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.