yianzzkf6687@1.0.3
Malicious code in yianzzkf6687 (npm)
Analysis
Postinstall hook runs node scripts/postinstall.js which spawns a hidden, detached background process executing scripts/shell.js — a multi-method reverse shell targeting C2 host 114[.]67[.]90[.]67 across ports 3334, 4444, 443, 80, 8080, and 53. The payload uses Node net sockets (spawning /bin/sh -i on Linux or hidden PowerShell.exe on Windows with pipes to the TCP socket), Bash /dev/tcp, and Python 2/3 reverse shells. Additionally, an HTTP GET pingback on port 8333 exfiltrates the hostname, username, working directory, and OS platform/release to the same IP. Logs to /tmp/.npm-cache.log to disguise as npm cache activity. The package's index.js is a harmless decoy string-manipulation library to evade casual inspection.
- analyzed by
- Leitwacht
- first seen
- Jun 19, 2026, 08:40 AM
- analyzed
- Jun 19, 2026, 08:41 AM
Related advisories
- aikaf6688812@1.0.3
- stitch-design@0.1.0
- panrouter@5.0.0
- panrouter-admin@5.0.0
- chai-as-attested@6.0.3
- @yhong91/vibetime@0.1.0
- @public-for-cdao/providers@1.0.1
- set-proto-chain@1.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.