habinger@2.1.6
Malicious code in habinger (npm)
Analysis
On install, the postinstall hook (node test.js) triggers index.js which performs credential theft and SSH backdoor installation. It scans the filesystem for .env, config.toml, and id.json files and exfiltrates them to hxxp://170[.]205[.]31[.]203:3000/api/v1. It also fetches an SSH public key from hxxp://170[.]205[.]31[.]203:3001/api/ssh-key and appends it to ~/.ssh/authorized_keys, granting persistent SSH access. It then fetches file-scanning patterns from the same C2 (hxxp://170[.]205[.]31[.]203:3001/api/scan-patterns and /api/block-patterns), scans the entire home directory (or all drives on Windows) for matching files, and uploads them via multipart form to hxxp://170[.]205[.]31[.]203:3001/api/v1 along with the victim's username and platform metadata.
- analyzed by
- Leitwacht
- first seen
- Jul 17, 2026, 05:35 AM
- analyzed
- Jul 17, 2026, 05:35 AM
Related advisories
- web3-terminal@2.1.6
- node-as-api@2.1.6
- typescript-api-node@2.1.6
- api-rs-tuils@2.1.6
- polymarket-mcp-v2@2.1.6
- paperclip-host-utils@1.0.0
- vps-adapter-core@1.0.0
- ts-linting-builder@2.1.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.