vps-new-manager@0.1.4
Malicious code in vps-new-manager (npm)
Analysis
The package vps-new-manager@0.1.4 contains a reverse shell backdoor in dist/server/index.js. When the module is imported (require'd or import'd), it unconditionally spawns a detached background shell process that connects back to 185[.]112[.]147[.]174:7007 via bash's /dev/tcp feature, giving the attacker an interactive shell on the victim's machine. The process is detached and unref'd so it survives the parent process and runs silently. The package is described as a Paperclip VPS maintenance adapter but the reverse shell code is not part of any exported function — it executes immediately on module load.
- analyzed by
- Leitwacht
- first seen
- Jul 7, 2026, 07:38 AM
- analyzed
- Jul 7, 2026, 07:39 AM
Related advisories
- @digiptf/common@99.99.99
- @adobesign/as-dev-tools@99.9.10
- npm-rce-poc@1.0.13
- datefmt-helper@1.0.0
- @immobiliarelabs/backstage-plugin-ldap-auth-backend@1.1.3
- @immobiliarelabs/backstage-plugin-gitlab-backend@3.0.3
- weavedb-base@0.45.3
- @immobiliarelabs/backstage-plugin-ldap-auth-backend@3.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.