@caspianph/storyteller@1.1.13
Malicious code in @caspianph/storyteller (npm)
Analysis
The package's postinstall script (setup.cjs) contains obfuscated code that disables TLS certificate validation, contacts a hardcoded C2 server at 23[.]254[.]164[.]92:8000 via the path /update/49890878, downloads a second-stage payload, writes it to a temp directory with a random hex filename + '.json' extension, and executes it as a detached, hidden node process. The script then deletes itself to hide its tracks. The package's main entry point (index.js) is a benign "hello world" module serving as a decoy. No credentials or tokens are stolen — this is a remote access trojan that pulls arbitrary code from the C2 upon installation.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 07:59 AM
- analyzed
- Jun 16, 2026, 08:00 AM
Related advisories
- vite-plugin-vue-extend@1.0.9
- vfat-tools@2.0.0
- sickle-wrapper@0.2.0
- mailconfirmer@3.3.12
- redeem-onchain-sdk@1.0.1
- period-newline@0.1.0
- weight2loss@1.0.5
- gpt-terminal-cli@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.