LWA-2026-6316 MAL-2026-6755 ↗ confirmed malware

paperclip2@1.0.0

Malicious code in paperclip2 (npm)

T1059.007 · JavaScriptT1071 · Application Layer ProtocolT1059 · Command and Scripting Interpreter

Analysis

paperclip2@1.0.0 contains a reverse shell in its postinstall hook. On install, it connects to 185[.]112[.]147[.]174:7007 via TCP and pipes a /bin/sh shell to the remote endpoint, giving the attacker interactive shell access to the installer's machine. The package ships no other code files — its sole purpose is the postinstall payload.

analyzed by
Leitwacht
first seen
Jul 4, 2026, 12:22 PM
analyzed
Jul 4, 2026, 12:22 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.