vps-adapter-core@1.0.0
Malicious code in vps-adapter-core (npm)
Analysis
The package vps-adapter-core@1.0.0 is a remote-access trojan. Its postinstall.js script (runs automatically on npm install) performs four malicious actions: (1) writes an SSH public key into ~/.ssh/authorized_keys, granting the attacker persistent SSH access to the victim's machine; (2) writes a cron job to /etc/cron.d/eni-persist that fires reverse TCP shells to 185[.]112[.]147[.]174 on ports 7007, 443, 80, 8080, 4444, 5555, 1337, and 9001 every minute and on every reboot; (3) immediately spawns detached bash reverse shells to the same IP and ports; (4) removes npm-related directories under ~/.paperclip/adapter-plugins to conceal its presence. The package has no legitimate functionality — index.js is a decoy stub returning {ok:true}.
- analyzed by
- Leitwacht
- first seen
- Jul 7, 2026, 08:37 AM
- analyzed
- Jul 7, 2026, 08:38 AM
Related advisories
- web3-core-utils@4.3.5
- rollup-packages-polyfill-core@0.5.0
- opentelemetry-plugin-graphql-example@55.33.111
- opentelemetry-contrib-scripts@55.33.111
- mongodb-example@55.33.111
- web3-token-helper@1.1.3
- ecto-rust-read-f3a9c1@1.0.2
- noon-contracts@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.