node-procmetrics@1.0.6
Malicious code in node-procmetrics (npm)
T1059.007 · JavaScriptT1059.004 · Unix ShellT1071.001 · Web ProtocolsT1053.003 · CronT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 ChannelT1082 · System Information Discovery
Analysis
The postinstall hook in install.js deploys a persistent remote access trojan. It copies itself to /tmp/.pm-agent.js, spawns a detached background process, and installs a crontab entry for persistence. The agent polls hxxp://152[.]53[.]120[.]90/cmd/commands every second for commands, executes them via bash -c, and exfiltrates the output to hxxp://152[.]53[.]120[.]90/cmd/results. The C2 server can push arbitrary shell commands to the infected machine.
- analyzed by
- Leitwacht
- first seen
- Jul 13, 2026, 11:54 AM
- analyzed
- Jul 13, 2026, 11:54 AM
Related advisories
- chunk-parser@1.0.0
- paperclip-host-utils@1.0.0
- vps-adapter-core@1.0.0
- web3-token-helper@1.1.3
- ecto-rust-read-f3a9c1@1.0.2
- noon-contracts@1.0.0
- solana-web3-stable@1.0.0
- solana-rpc-client@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.