entropyeasybots@2.0.2
Malicious code in entropyeasybots (npm)
T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1543.002 · Systemd ServiceT1027 · Obfuscated Files or InformationT1480 · Execution GuardrailsT1071.001 · Web ProtocolsT1572 · Protocol TunnelingT1082 · System Information Discovery
Analysis
entropyeasybots@2.0.2 is a reverse shell trojan. On install, the postinstall hook runs install.js which registers a systemd service named 'CustomBot' via the node-linux package for persistence. The main index.js spawns a detached background copy of itself, then opens a TCP reverse shell to 85[.]137[.]253[.]124 on port 1111, piping /bin/sh to give the attacker remote shell access. The C2 IP is base64-encoded in the source. The package also checks the INVOCATION_ID environment variable to detect container/sandbox environments.
- analyzed by
- Leitwacht
- first seen
- Aug 3, 2026, 02:40 PM
- analyzed
- Aug 3, 2026, 02:44 PM
Related advisories
- @marketfront/bannerpopup@7.0.0
- @digitalcnzz/embedded-sdk@1.0.7
- util-free-ports@3.1.2
- stringfy-utils-kit@1.0.0
- sort-btree@2.1.4
- macos-ci-utils@1.0.1
- index-ulid@3.0.2
- obfus-jsxy@3.2.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.