LWA-2026-7631 MAL-2026-11539 ↗ confirmed malware

entropyeasybots@2.0.2

Malicious code in entropyeasybots (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1543.002 · Systemd ServiceT1027 · Obfuscated Files or InformationT1480 · Execution GuardrailsT1071.001 · Web ProtocolsT1572 · Protocol TunnelingT1082 · System Information Discovery

Analysis

entropyeasybots@2.0.2 is a reverse shell trojan. On install, the postinstall hook runs install.js which registers a systemd service named 'CustomBot' via the node-linux package for persistence. The main index.js spawns a detached background copy of itself, then opens a TCP reverse shell to 85[.]137[.]253[.]124 on port 1111, piping /bin/sh to give the attacker remote shell access. The C2 IP is base64-encoded in the source. The package also checks the INVOCATION_ID environment variable to detect container/sandbox environments.

analyzed by
Leitwacht
first seen
Aug 3, 2026, 02:40 PM
analyzed
Aug 3, 2026, 02:44 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.