{"id":"MAL-2026-16188","summary":"Malicious code in strapi-plugin-rs-meeb322k (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6293e711bb544c63fcc29178febb4100cee80f9cbd1060b3c3173445419a172c)\npostinstall.js runs unconditionally during `npm install` via scripts.postinstall and executes a bash reverse shell that redirects an interactive shell's stdio to a TCP socket at the hardcoded external address 14.225.210.85:443, giving that remote endpoint arbitrary command execution on the installer's host. The package description self-labels as a reverse-shell payload for Strapi, and the name mimics the strapi-plugin-* namespace.\n","modified":"2026-09-15T16:31:26.681653761Z","published":"2026-09-15T15:52:54Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-09-15T16:19:13.993874077Z","modified_time":"2026-09-15T15:52:54Z","sha256":"6293e711bb544c63fcc29178febb4100cee80f9cbd1060b3c3173445419a172c","source":"amazon-inspector","versions":["3.6.8"],"id":"IN-MAL-2026-020047"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/strapi-plugin-rs-meeb322k/v/3.6.8"}],"affected":[{"package":{"name":"strapi-plugin-rs-meeb322k","ecosystem":"npm","purl":"pkg:npm/strapi-plugin-rs-meeb322k"},"versions":["3.6.8"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/strapi-plugin-rs-meeb322k/MAL-2026-16188.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"sha256":"ea7e8660683da8da4900fcf28c7d5d11f039bbcd8d9e34566b48c388323ea18a","tlsh":"5901bd5426ea673a52338dedea07882b63430e057039e8233dcc03130fc6c9c9441afd","path":"postinstall.js"}],"package_integrity":[{"hashes":{"sha1":"c3fba5284d97fb167eb4946fe9ed7e92d35b9d97","sha512_sri":"sha512-RsQxlMwLKVkrx4jEgOyDTAnlGv/i+alLm5Qw/2eRNRQSpKxQdXt34HYdoxFWU74NTW2Qzqit1sZnXX9lSULEpw=="},"filename":"strapi-plugin-rs-meeb322k-3.6.8.tgz"}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}