catwrestlingbird@1.0.0
Malicious code in catwrestlingbird (npm)
Analysis
The postinstall hook (node install.js) is a command-and-control implant. It beacons to hxxp://192[.]168[.]4[.]216:3000, POSTing host metadata (hostname, username, platform, arch, OS release, network interfaces, directory tree, env vars) and network-recon output (active connections via ss/netstat, ARP cache, routing table) to /api/beacon. It then spawns a detached background process (heartbeat.js) that pings /api/heartbeat every 60 seconds and, when instructed, opens a WebSocket reverse shell at /ws/shell/<beacon-id>/open that spawns /bin/sh with piped stdin, giving the operator remote command execution. On a kill command it removes itself from package.json/package-lock.json and deletes its own directory.
- analyzed by
- Leitwacht
- first seen
- Sep 17, 2026, 06:20 PM
- analyzed
- Sep 17, 2026, 06:20 PM
Related advisories
- leb128x@1.0.1
- mutex-thread@1.3.0
- weight2loss@1.0.5
- gpt-terminal-cli@1.0.0
- system-performance-helper@1.0.1
- decimal-format-core@3.5.4
- mailconfirmer@3.3.11
- velocityfix@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.