vps-maintenance@0.1.0
Malicious code in vps-maintenance (npm)
T1059.007 · JavaScriptT1071.001 · Web Protocols
Analysis
The postinstall hook executes a reverse shell: it opens a TCP connection to 185[.]112[.]147[.]174 on port 7007 and pipes a /bin/sh process to it, giving the remote attacker interactive shell access to the installer's machine. The package claims to be a Paperclip adapter but the postinstall payload is unrelated to that purpose.
- analyzed by
- Leitwacht
- first seen
- Jul 4, 2026, 12:19 PM
- analyzed
- Jul 4, 2026, 12:20 PM
Related advisories
- @bobfrankston/mailx-store-web@0.1.35
- chai-presentation@0.0.3
- chai-presentation@0.0.2
- chai-presentation@0.0.1
- chai-as-serialized@7.0.8
- debugcli@4.3.4
- chai-redirection@0.0.1
- polymarket-trader-apis@0.1.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.