app-data-ist@2.1.6
Malicious code in app-data-ist (npm)
Analysis
The package app-data-ist@2.1.6 is a dependency-confusion attack that depends on npm packages named 'child_process' and 'os' (typosquatting Node.js core built-in modules). Its postinstall hook runs a script that: (1) scans the current directory and home directory for credential files (id.json, config.toml, .env) and exfiltrates them via HTTP POST to 170[.]205[.]31[.]203:3000/api/v1; (2) fetches an SSH public key and file-scan patterns from 170[.]205[.]31[.]203:3001/api/ssh-key, /api/scan-patterns, and /api/block-patterns; (3) on Linux, appends the attacker's SSH key to ~/.ssh/authorized_keys, creating a persistent backdoor; (4) scans the entire home directory (or all Windows user drives) for files matching the fetched patterns and batch-uploads them to 170[.]205[.]31[.]203:3001/api/v1. The package description is unrelated to its actual behaviour.
- analyzed by
- Leitwacht
- first seen
- Jul 21, 2026, 04:38 AM
- analyzed
- Jul 21, 2026, 04:38 AM
Related advisories
- application-util@2.1.6
- ddaxx@1.0.0
- ts-einkle@1.0.9
- ref-slot@1.0.9
- buffer-wrap-67d7@1.0.0
- prettlog@1.0.10
- ts-ecro@0.0.6
- app-kst-engine@2.1.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.