entropyeasybots@2.0.2
Malicious code in entropyeasybots (npm)
T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1543.002 · Systemd ServiceT1027 · Obfuscated Files or InformationT1480 · Execution GuardrailsT1071.001 · Web ProtocolsT1572 · Protocol TunnelingT1082 · System Information Discovery
Analysis
entropyeasybots@2.0.2 is a reverse shell trojan. On install, the postinstall hook runs install.js which registers a systemd service named 'CustomBot' via the node-linux package for persistence. The main index.js spawns a detached background copy of itself, then opens a TCP reverse shell to 85[.]137[.]253[.]124 on port 1111, piping /bin/sh to give the attacker remote shell access. The C2 IP is base64-encoded in the source. The package also checks the INVOCATION_ID environment variable to detect container/sandbox environments.
- analyzed by
- Leitwacht
- first seen
- Aug 3, 2026, 02:40 PM
- analyzed
- Aug 3, 2026, 02:44 PM
Related advisories
- a.poltoradnev-package-b@33.9.1
- pfp-forms-independent-sme-glossary-anchor@20.4.4
- twork-data-services-ng14-aggregator-api-v2-data-view-user-b2b-create-deal-mf-config@20.6.1
- form-bnpl-dolyame-component-object@20.8.9
- tinkoff-pfp-atom-desktop-carousel@20.8.8
- streak-metrics-math@1.0.1
- prisma-callback@1.0.0
- space-items@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.