LWA-2026-6288 MAL-2026-6757 ↗ confirmed malware

vps-maintenance-paperclip-adapter@0.1.1

Malicious code in vps-maintenance-paperclip-adapter (npm)

T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages

Analysis

The postinstall hook in package.json executes a reverse shell: it opens a TCP connection to 185[.]112[.]147[.]174 on port 7007 and pipes the connection to /bin/sh, giving the remote operator full shell access on the machine where the package is installed. The hook runs automatically on npm install.

analyzed by
Leitwacht
first seen
Jul 3, 2026, 11:27 AM
analyzed
Jul 3, 2026, 11:29 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.