strapi-plugin-maylog-meeb@3.6.8
Malicious code in strapi-plugin-maylog-meeb (npm)
T1059 · Command and Scripting InterpreterT1059.007 · JavaScriptT1071 · Application Layer Protocol
Analysis
The package's postinstall hook executes a reverse shell. It connects to 14[.]225[.]210[.]85:80 and spawns an interactive shell via python3 (socket + pty.spawn), retrying every 10 seconds up to 5 attempts and logging progress to /tmp/postinstall-revshell.log. Installing the package gives the remote host a shell on the installer's machine.
- analyzed by
- Leitwacht
- first seen
- Sep 16, 2026, 09:56 AM
- analyzed
- Sep 16, 2026, 09:57 AM
Related advisories
- strapi-plugin-perev-meeb@3.6.8
- strapi-plugin-rsh-meeb322k@3.6.8
- strapi-plugin-revsh-meeb322k@3.6.8
- strapi-plugin-revs-meeb322k@3.6.8
- strapi-plugin-rs-meeb322k@3.6.8
- n8n-nodes-healthmon@1.0.0
- tailwind-form-kit@0.6.2
- hydration-ui-pkg@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.