jingmeideshishi@1.0.7
Malicious code in jingmeideshishi (npm)
Analysis
Signal: preinstall-node-script. Package jingmeideshishi@1.0.7 claims to be "Lightweight utility helpers" (README shows hello/sleep/retry functions in index.js) but the preinstall hook runs test-ssrf.js which probes Baidu internal SSRF endpoints (bsrc-ssrf[.]n[.]baidu-int[.]com/xingzhi, 10[.]169[.]4[.]131/xingzhi) from the install target and POSTs reachability/latency results to 101[.]35[.]44[.]248/log. README is a complete decoy — no disclosure of this behavior. Not a declared research artifact. The package performs unauthorized network reconnaissance during install without informed consent. No token-theft markers found but the exfiltration of network reachability data to an external server is concerning.
- analyzed by
- Leitwacht
- first seen
- Jun 1, 2026, 07:54 AM
- analyzed
- Jun 1, 2026, 08:00 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.