aikaf6688812@1.0.3
Malicious code in aikaf6688812 (npm)
Analysis
Package aikaf6688812 (advertised as a string utility library) executes a TCP reverse shell upon `npm install`. The postinstall hook spawns a detached Node.js process running scripts/shell.js, which opens a raw TCP socket to 114[.]67[.]90[.]67:3334, connects it to /bin/sh -i (or powershell.exe -NoLogo -NonInteractive -NoProfile -ExecutionPolicy Bypass -WindowStyle hidden on Windows), and pipes stdin/stdout/stderr bidirectionally. The shell automatically reconnects every 10 seconds on disconnect or error. The installer's shell is fully exposed to the remote attacker while the package pretends to export harmless string functions (capitalize, truncate, camelCase, etc.).
- analyzed by
- Leitwacht
- first seen
- Jun 19, 2026, 08:28 AM
- analyzed
- Jun 19, 2026, 08:28 AM
Related advisories
- request-logger-canary@1.0.0
- obfus-jsxy@3.2.0
- ecto-rust-read-f3a9c1@1.0.2
- aikaf668897@1.0.3
- yian666aikf@1.0.3
- env-config-f281@1.0.0
- color-utils-eee0@1.0.0
- hex-conv-ae7a@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.