system-drive@1.0.0
Malicious code in system-drive (npm)
Analysis
system-drive@1.0.0 installs a persistent backdoor that exposes all user home directories over the internet. When run, the package writes a JavaScript payload that starts an HTTP file server (with basic auth credentials systum/systum) serving /Users (macOS/Linux) or C:\Users (Windows). It opens a public tunnel via localtunnel[.]me and sends the tunnel URL to linksaver-psi[.]vercel[.]app/api/save. It then installs pm2 and configures the payload to restart automatically on system boot. This gives the attacker remote access to all user files including .ssh keys, .aws credentials, and .npmrc tokens.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 01:03 PM
- analyzed
- Jun 14, 2026, 01:03 PM
Related advisories
- seed-to-private@1.0.1
- index-ulid@3.0.2
- npm-scanner@1.0.0
- noon-contracts@1.0.0
- nodecheck-health@1.0.0
- hex-type@3.0.2
- os-ulid-void@3.0.2
- map-streak-kit@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.