mongodb-example@55.33.111
Malicious code in mongodb-example (npm)
Analysis
Install-environment probe / payload stager: mongodb-example@55.33.111. A postinstall hook calls does.js, which (1) creates a stealth directory at ~/.local/share/package-install or AppData\Proofs\package-install; (2) writes a host fingerprint beacon (hostname, platform, arch, timestamp) to install_log.txt; and (3) drops and chmods a helper.sh/helper.exe placeholder executable. The declared postinstall path (scripts/does.js) mismatches the actual file (does.js), a packaging error, but the intent to probe the install environment and stage a payload on disk is unambiguous.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 07:42 PM
- analyzed
- Jun 10, 2026, 07:44 PM
Related advisories
- vps-adapter-core@1.0.0
- web3-core-utils@4.3.5
- rollup-packages-polyfill-core@0.5.0
- opentelemetry-plugin-graphql-example@55.33.111
- opentelemetry-contrib-scripts@55.33.111
- modulyn@1.0.1
- moltbook-api-helper@1.0.1
- miro-plugin-tag-crawler@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.