LWA-2026-6366 MAL-2026-6981 ↗ confirmed malware

paperclip-adapter-helpers@1.0.4

Malicious code in paperclip-adapter-helpers (npm)

Analysis

Combosquat package impersonating the Paperclip AI platform's adapter ecosystem. On import, the top-level code in dist/server/index.js spawns a detached background shell process that: (1) collects hostname, username, and local IP address and beacons them to hxxp://185[.]112[.]147[.]174:7007/beacon via curl or wget; (2) polls hxxp://185[.]112[.]147[.]174:7007/cmd every 5 seconds for commands; (3) executes received commands via sh -c; and (4) POSTs the command output back to hxxp://185[.]112[.]147[.]174:7007/out. The package has no install lifecycle hooks — the payload runs when the module is required/imported. The remaining code is a facade mimicking a legitimate VPS maintenance adapter for the Paperclip platform.

analyzed by
Leitwacht
first seen
Jul 7, 2026, 07:23 AM
analyzed
Jul 7, 2026, 07:23 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.