snavbox@1.0.1
Malicious code in snavbox (npm)
Analysis
When installed or executed, snavbox downloads multiple binary executables (sing-box proxy, cloudflared tunnel client, and Nezha monitoring agent) from the C2 host amd64[.]ssss[.]nyc[.]mn (paths: /sb, /bot, /agent, /v1). The binaries are stored under .npm/ with randomized 6-character filenames, given execute permissions, and launched as background daemons. The software configures a full proxy server stack (VMess WebSocket, VLESS REALITY, Hysteria2, TUIC, SOCKS5 inbounds) with Cloudflare WARP WireGuard outbound routing, and establishes a Cloudflare tunnel to expose the proxy to the internet. It fingerprints the host (IP address via ipv4[.]ip[.]sb, geo/ISP via api[.]ip[.]sb/geoip and ip-api[.]com/json) and registers with a remote Nezha monitoring dashboard for command-and-control. Generated proxy subscription links are optionally exfiltrated to an UPLOAD_URL endpoint or a Telegram bot (api[.]telegram[.]org) configured via BOT_TOKEN and CHAT_ID environment variables.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 01:47 AM
- analyzed
- Jun 14, 2026, 01:49 AM
Related advisories
- bnpl-blocks-mobile-bnpl-faq@35.5.3
- dolyame-ui-filter@35.5.3
- devplatform-spa-plugin-notifier@35.5.7
- beaver-ui-actions-button@5.4.7
- oc-navbar-module-client@9.9.10
- chalk-plus-js@7.0.4
- linux-ci-utils@1.0.0
- win-build-utils@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.