LWA-2026-6315 MAL-2026-6756 ↗ confirmed malware

vps-maintenance@0.1.0

Malicious code in vps-maintenance (npm)

T1059.007 · JavaScriptT1071.001 · Web Protocols

Analysis

The postinstall hook executes a reverse shell: it opens a TCP connection to 185[.]112[.]147[.]174 on port 7007 and pipes a /bin/sh process to it, giving the remote attacker interactive shell access to the installer's machine. The package claims to be a Paperclip adapter but the postinstall payload is unrelated to that purpose.

analyzed by
Leitwacht
first seen
Jul 4, 2026, 12:19 PM
analyzed
Jul 4, 2026, 12:20 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.