LWA-2026-4300 MAL-2026-5704 ↗ confirmed malware

friendly-greeter-demo@1.0.1

Malicious code in friendly-greeter-demo (npm)

Analysis

This package presents itself as a tiny educational greeting library, but its main module embeds a fully functional command-and-control backdoor that runs automatically when the module is imported. On load it collects the host name and platform and registers the victim with a hardcoded remote server over plain HTTP, then polls that server for a command. Any command returned is executed on the host via the system shell, and the combined stdout/stderr is sent back to the operator. All errors are silently suppressed to avoid detection. This gives the attacker arbitrary remote code execution on any machine that imports the package.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 01:56 PM
analyzed
Jun 28, 2026, 06:27 AM
weekly installs
1,816

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.