npmamzs@1.1.1
Malicious code in npmamzs (npm)
Analysis
npmamzs@1.1.1 is a supply-chain attack package with no description, README, or legitimate functionality. Its postinstall hook runs index.js, which fetches a remote shell script from an ngrok tunnel at hxxps://reunionistic-keagan-unfestively[.]ngrok-free[.]dev/rev.sh and executes it via bash in a detached child process. Its sole purpose is downloading and running a second-stage payload from attacker-controlled infrastructure.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 03:08 PM
- analyzed
- Jun 11, 2026, 03:30 PM
Related advisories
- npmamzs@1.1.4 same package
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.