{"id":"MAL-2026-16228","summary":"Malicious code in strapi-plugin-ccrev-meeb (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (cbcdfb404042de180795640d5ea266d8fe50afff5d180b3da0eab17f979369f3)\npostinstall.js executes automatically on `npm install` and opens a bash reverse shell via /dev/tcp redirection to the hardcoded remote endpoint 14.225.210.85:80, retrying up to 5 times. Execution is gated by an os.hostname() check against 'ubuntu-fc-uvm', so the payload only fires on installers whose hostname matches that value; on matching hosts the attacker obtains an interactive shell on the installer's machine. The package name mimics an unrelated Strapi plugin, and no legitimate plugin functionality is present alongside the postinstall payload.\n","modified":"2026-09-16T14:30:06.926607218Z","published":"2026-09-16T13:59:29Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["3.6.8"],"id":"IN-MAL-2026-020105","import_time":"2026-09-16T14:19:38.22554901Z","modified_time":"2026-09-16T13:59:29Z","sha256":"cbcdfb404042de180795640d5ea266d8fe50afff5d180b3da0eab17f979369f3"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/strapi-plugin-ccrev-meeb/v/3.6.8"}],"affected":[{"package":{"name":"strapi-plugin-ccrev-meeb","ecosystem":"npm","purl":"pkg:npm/strapi-plugin-ccrev-meeb"},"versions":["3.6.8"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"hashes":{"sha1":"07a3fe2ad8e90fc0a44653fde45170f0767a4399","sha512_sri":"sha512-y1NEZ102UteiQ9zcbymvPz7vlu/BZ58ykmFp7VcsAR+2fFfdhFRehBU3yPGJgEyhmYfAYdJ+alENXhvUtIueVA=="},"filename":"strapi-plugin-ccrev-meeb-3.6.8.tgz"}],"evidence_files":[{"tlsh":"ef411eed05bf2b3962338ce9522b8097d52741023516d278b5dc8b43bfc4d9ac631afa","path":"postinstall.js","sha256":"59958a5b6cf205abf8e3c05e62d883c008dafcd91abe907dda3d0f2bdb95a5a2"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/strapi-plugin-ccrev-meeb/MAL-2026-16228.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}