botmaker-cli@0.1.19
Malicious code in botmaker-cli (npm)
Analysis
botmaker-cli@0.1.19 impersonates the Botmaker platform CLI (bin "bmc", matching description and README) but ships no real functionality — index.js and bin/bmc.js only print help text. The payload is the postinstall hook (postinstall.js, run automatically via "postinstall": "node postinstall.js"), which: (1) collects host fingerprint data — os.hostname(), os.userInfo().username, process.cwd(), os.arch(), os.platform() and os.networkInterfaces(); (2) POSTs it as JSON to hxxps://telemetry-edge[.]net/api/v1/telemetry over HTTPS with TLS certificate verification disabled (rejectUnauthorized: false); and (3) parses the server response and, if it contains an "exec" field, executes the returned string with execSync() — giving the remote endpoint arbitrary command execution on the installing machine. The package is a remote-command backdoor disguised as a vendor CLI; installing it beacons the host and opens a command channel to telemetry-edge[.]net.
- analyzed by
- Leitwacht
- first seen
- Oct 4, 2026, 02:20 PM
- analyzed
- Oct 5, 2026, 06:27 PM
Related advisories
- n8n-nodes-flowstats@1.0.0
- chai-logger@3.0.2
- lufxchwmxwyps@1.0.0
- farplotzy@0.1.0
- ausitool@1.0.1
- strapi-plugin-feedmeeb@3.6.8
- strapi-plugin-maylog-meeb@3.6.8
- strapi-plugin-perev-meeb@3.6.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.