ecto-rust-read-f3a9c1@1.0.2
Malicious code in ecto-rust-read-f3a9c1 (npm)
Analysis
postinstall.js deploys a multi-stage implant on the victim's system. The package ships only a stub index.js (module.exports={}); its entire purpose is the postinstall hook. The hook first runs isRealTarget() to evade sandboxes — it exits immediately if cwd contains /tmp/ (common analysis sandboxes) or hostname contains hetzner/nijin/ec2.internal — and only proceeds on CI/CD-like hosts (hex hostname in /app/ or registry pointing to nexus.local/verdaccio). Once the guard passes, it: (1) writes a reverse-shell script to /usr/local/bin/.spectral-shell that connects back to snnkj-159-153-180-200[.]run[.]pinggy-free[.]link:38493 via bash /dev/tcp; (2) installs a root cron job to /etc/cron.d/spectral-shell (with user-crontab fallback) so the shell reconnects every minute; (3) starts the cron daemon if not running; (4) spawns the reverse shell immediately as a detached background process; (5) sends an HTTP PUT beacon to /api/modules/ECT-472839 at multiple C2 endpoints including 154[.]57[.]164[.]71:31289, registering the infection with the operator.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 02:46 PM
- analyzed
- Jun 11, 2026, 02:46 PM
Related advisories
- aikaf668897@1.0.3
- aikaf6688812@1.0.3
- request-logger-canary@1.0.0
- obfus-jsxy@3.2.0
- devplatform-spa-plugin-module-loader@35.8.5
- entropyeasybots@2.0.2
- @marketfront/bannerpopup@7.0.0
- @digitalcnzz/embedded-sdk@1.0.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.