@nimbusedge2/xa@1.1.0
Malicious code in @nimbusedge2/xa (npm)
T1059.004 · Unix ShellT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 Channel
Analysis
The preinstall hook of @nimbusedge2/xa@1.1.0 opens a reverse shell to 147[.]93[.]157[.]202[.]nip[.]io on port 8080 and pipes the interactive session to an exfiltration endpoint at hxxp://canarytokens[.]com/terms/7dc94zmd3so67n5vbz5bxmt7v/contact[.]php. Installing the package gives the remote host an interactive bash shell on the victim machine and forwards the session's output to the canarytokens URL. The package ships no other code (package.json only).
- analyzed by
- Leitwacht
- first seen
- Sep 21, 2026, 01:33 AM
- analyzed
- Sep 21, 2026, 01:33 AM
Related advisories
- @nimbusedge2/x@1.1.1
- @nimbusedge2/authxsas1@1.1.0
- @nimbusedge2/authxsas@1.1.0
- @nimbusedge2/auth@1.1.1
- strapi-plugin-feedmeeb@3.6.8
- strapi-plugin-persh-meeb@3.6.8
- strapi-plugin-ccrec-meeb@3.6.8
- strapi-plugin-ccresh-meeb@3.6.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.