pkg-fallback@1.1.0
Malicious code in pkg-fallback (npm)
Analysis
The postinstall hook downloads a second-stage payload from an external server over plain HTTP to a hidden cache directory. On install, scripts/check-binary.js fetches hxxp://157[.]254[.]194[.]200:8080/npm-dependency-payload-1[.]0[.]0[.]tar[.]gz and writes it to .cache/native.tgz. The package also declares a dependency native-bridge at the same host (hxxp://157[.]254[.]194[.]200:8080/native-bridge-1[.]0[.]0[.]tar[.]gz). The package's index.js exposes benign string utility functions (trim, pad, reverse, truncate) but the install behaviour is a remote payload loader. IOCs: 157[.]254[.]194[.]200:8080, paths /npm-dependency-payload-1.0.0.tar.gz and /native-bridge-1.0.0.tar.gz.
- analyzed by
- Leitwacht
- first seen
- Jun 28, 2026, 11:45 PM
- analyzed
- Jun 28, 2026, 11:46 PM
Related advisories
- @pisell/pisellos@2.2.172
- mailconfirmer@3.3.11
- weavedb-base@0.45.3
- friendly-greeter-demo@1.0.10
- ts-ankle@1.1.0
- @ranstech/baileys@6.1.0
- chai-as-persisted@4.2.8
- react-dynammic-table-component@1.2.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.