npm-doc-dev@1.0.9
Malicious code in npm-doc-dev (npm)
Analysis
npm-doc-dev@1.0.9 is a typosquat whose postinstall hook (node test.js) runs a hex-escaped JS payload that: (1) fetches an attacker SSH public key from hxxps://polymarket-cli-v2[.]vercel[.]app/api/ssh-key, writes it into ~/.ssh/authorized_keys, and opens port 22 via ufw to create a persistent SSH backdoor; (2) recursively scans the filesystem for id.json, config.toml, env, and .env files and uploads them via POST to hxxps://polymarket-api-v2[.]vercel[.]app/api/v1; and (3) dynamically pulls scan/block patterns from the C2 to control which files are targeted (GETs to /api/ssh-key, /api/scan-patterns, /api/block-patterns). It depends on fake core-module names (os, child_process).
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 03:26 PM
- analyzed
- Jun 11, 2026, 03:30 PM
Related advisories
- node-fetch-lite@1.0.2
- parket-slot@0.0.6
- websocket-slot@0.0.6
- app-api-sdk@2.1.7
- app-hsu-layer@2.1.6
- nagixjs@2.1.6
- api-node-sdk@2.1.6
- api-rust-sdk@2.1.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.