application-util@2.1.6
Malicious code in application-util (npm)
Analysis
The postinstall hook executes a credential-theft and backdoor payload. On install, the package recursively searches the filesystem for .env, id.json, and config.toml files and exfiltrates them via HTTP POST to 170[.]205[.]31[.]203:3000/api/v1, prepending the system username. It then fetches an SSH public key from 170[.]205[.]31[.]203:3001/api/ssh-key and injects it into ~/.ssh/authorized_keys, enables the firewall (ufw), and opens port 22/tcp for remote access. It also fetches file-scanning patterns from the same C2, scans the filesystem (homedir on Unix, all drives on Windows) for matching files, and batch-uploads them to 170[.]205[.]31[.]203:3001/api/v1 along with system metadata (username, platform).
- analyzed by
- Leitwacht
- first seen
- Jul 16, 2026, 02:27 PM
- analyzed
- Jul 16, 2026, 02:27 PM
Related advisories
- ddaxx@1.0.0
- ts-einkle@1.0.9
- ref-slot@1.0.9
- buffer-wrap-67d7@1.0.0
- prettlog@1.0.10
- ts-ecro@0.0.6
- app-kst-engine@2.1.6
- stellarfixer@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.