npmamzs@1.1.4
Malicious code in npmamzs (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
npmamzs@1.1.4 is a supply-chain attack package with no description, README, or legitimate functionality. Its postinstall hook runs index.js, which fetches a remote shell script from an ngrok tunnel at hxxps://reunionistic-keagan-unfestively[.]ngrok-free[.]dev/rev.sh and executes it via bash in a detached child process. Its sole purpose is downloading and running a second-stage payload from attacker-controlled infrastructure.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 03:08 PM
- analyzed
- Jun 11, 2026, 03:30 PM
Related advisories
- npmamzs@1.1.1 same package
- npm-doc-dev@1.0.9
- ecto-rust-read-f3a9c1@1.0.2
- chalk-plus-js@7.0.4
- express-initial@12.1.7
- node-pino@2.3.2
- sn-internal-testjgsakjdkjadkjahsdkjad@2.1.1
- node-env-resolver-nextjs@7.4.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.