friendly-greeter-demo@1.0.1
Malicious code in friendly-greeter-demo (npm)
Analysis
This package presents itself as a tiny educational greeting library, but its main module embeds a fully functional command-and-control backdoor that runs automatically when the module is imported. On load it collects the host name and platform and registers the victim with a hardcoded remote server over plain HTTP, then polls that server for a command. Any command returned is executed on the host via the system shell, and the combined stdout/stderr is sent back to the operator. All errors are silently suppressed to avoid detection. This gives the attacker arbitrary remote code execution on any machine that imports the package.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 01:56 PM
- analyzed
- Jun 28, 2026, 06:27 AM
- weekly installs
- 1,816
Related advisories
- friendly-greeter-demo@1.0.10 same package
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.