prisma-callback@1.0.0
Malicious code in prisma-callback (npm)
T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1059.004 · Unix ShellT1071.001 · Web ProtocolsT1572 · Protocol TunnelingT1546.016 · Installer Packages
Analysis
A combosquat of the Prisma ORM. The preinstall hook (node ./scripts/only-allow-pnpm.js) masquerades as a standard package-manager guard but appends a raw TCP reverse shell: it opens a socket to 52[.]74[.]242[.]200:8851 and spawns /bin/sh -i with stdin/stdout/stderr piped through the socket, giving an attacker an interactive shell on any machine that installs the package.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 01:29 PM
- analyzed
- Jun 12, 2026, 01:31 PM
Related advisories
- streak-map-kit@1.0.0
- bigops-chats@35.9.6
- bigops-auth-cache@35.3.9
- bigops-cobrowsing@35.4.9
- entropyeasybots@2.0.2
- a.poltoradnev-package-b@33.9.1
- pfp-forms-independent-sme-glossary-anchor@20.4.4
- twork-data-services-ng14-aggregator-api-v2-data-view-user-b2b-create-deal-mf-config@20.6.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.