vps-maintenance-paperclip-adapter@0.1.1
Malicious code in vps-maintenance-paperclip-adapter (npm)
T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages
Analysis
The postinstall hook in package.json executes a reverse shell: it opens a TCP connection to 185[.]112[.]147[.]174 on port 7007 and pipes the connection to /bin/sh, giving the remote operator full shell access on the machine where the package is installed. The hook runs automatically on npm install.
- analyzed by
- Leitwacht
- first seen
- Jul 3, 2026, 11:27 AM
- analyzed
- Jul 3, 2026, 11:29 AM
Related advisories
- @public-for-cdao/providers@1.0.1
- @ravespaceio/browser-input@99.0.1
- react-copy-lite@1.0.1
- prisma-callback@1.0.0
- martinez-polygon-clipping-tony@0.9.0
- @klapp-sca/routes@99.0.1
- @klapp-login-platform/routes@99.0.2
- ai-sdk-helpers@1.2.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.