LWA-2026-4754 MAL-2026-3770 ↗ confirmed malware

prisma-callback@1.0.0

Malicious code in prisma-callback (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1059.004 · Unix ShellT1071.001 · Web ProtocolsT1572 · Protocol TunnelingT1546.016 · Installer Packages

Analysis

A combosquat of the Prisma ORM. The preinstall hook (node ./scripts/only-allow-pnpm.js) masquerades as a standard package-manager guard but appends a raw TCP reverse shell: it opens a socket to 52[.]74[.]242[.]200:8851 and spawns /bin/sh -i with stdin/stdout/stderr piped through the socket, giving an attacker an interactive shell on any machine that installs the package.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 01:29 PM
analyzed
Jun 12, 2026, 01:31 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.