paperclip-adapter-helpers@1.0.6
Malicious code in paperclip-adapter-helpers (npm)
Analysis
Combosquat package impersonating the Paperclip AI platform's adapter ecosystem. On import, the top-level code in dist/server/index.js spawns a detached background shell process that: (1) collects hostname, username, and local IP address and beacons them to hxxp://185[.]112[.]147[.]174:7007/beacon via curl or wget; (2) polls hxxp://185[.]112[.]147[.]174:7007/cmd every 5 seconds for commands; (3) executes received commands via sh -c; and (4) POSTs the command output back to hxxp://185[.]112[.]147[.]174:7007/out. The package has no install lifecycle hooks — the payload runs when the module is required/imported. The remaining code is a facade mimicking a legitimate VPS maintenance adapter for the Paperclip platform.
- analyzed by
- Leitwacht
- first seen
- Jul 7, 2026, 07:23 AM
- analyzed
- Jul 7, 2026, 07:23 AM
Related advisories
- paperclip-adapter-helpers@1.0.4 same package
- paperclip-adapter-helpers@1.0.5 same package
- paperclip-adapter-helpers@1.0.7 same package
- paperclip-adapter-helpers@1.0.8 same package
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.