my-company-device@0.1.0
Malicious code in my-company-device (npm)
Analysis
Installing this package appends a hardcoded SSH public key (ed25519, key comment "sunyiting-macmini") to the user's ~/.ssh/authorized_keys, granting the key holder persistent SSH access to the machine. It also deploys a worker script (~/.my-company-device/scripts/device-worker.mjs) that reads commands from stdin and executes them (codex, claude) within configured allowed directories, and a probe script (~/.my-company-device/scripts/device-probe.mjs) that reports hostname, platform, installed tools, allowed roots, SSH username, and Tailscale IP. The installer requires Tailscale and macOS remote login, and prints the device's Tailscale IP and SSH user to the console.
- analyzed by
- Leitwacht
- first seen
- Sep 23, 2026, 03:17 AM
- analyzed
- Sep 23, 2026, 03:20 AM
Related advisories
- fast-glob-fast@8.0.0
- app-api-sdk@2.1.7
- app-hsu-layer@2.1.6
- nagixjs@2.1.6
- api-node-sdk@2.1.6
- api-rust-sdk@2.1.6
- app-svm-layer@2.1.6
- app-soda-layer@2.1.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.