paperclip2@1.0.0
Malicious code in paperclip2 (npm)
T1059.007 · JavaScriptT1071 · Application Layer ProtocolT1059 · Command and Scripting Interpreter
Analysis
paperclip2@1.0.0 contains a reverse shell in its postinstall hook. On install, it connects to 185[.]112[.]147[.]174:7007 via TCP and pipes a /bin/sh shell to the remote endpoint, giving the attacker interactive shell access to the installer's machine. The package ships no other code files — its sole purpose is the postinstall payload.
- analyzed by
- Leitwacht
- first seen
- Jul 4, 2026, 12:22 PM
- analyzed
- Jul 4, 2026, 12:22 PM
Related advisories
- compose-logger-stand@1.0.126
- bandkit@1.0.7
- yoshino_s_test_evil@1.0.0
- transform-es2015-destructuring@6.24.1
- period-newline@0.1.0
- nodecheck-health@1.0.0
- solana-web3-stable@1.0.0
- solana-rpc-client@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.