{"id":"MAL-2026-16232","summary":"Malicious code in strapi-plugin-listcc-meeb (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (63bef6a3804e282781fb0eaea1ffd045ef3b236aefd0668de11549aba1ada8b0)\nstrapi-plugin-listcc-meeb@3.6.8 declares scripts.postinstall = 'node postinstall.js' (and points main at the same file), so `npm install` auto-executes postinstall.js. That script spawns a Python one-liner via child_process that opens a socket to the hardcoded IP 14.225.210.85:80 and attaches a PTY-backed /bin/sh to the remote peer, yielding an interactive reverse shell on the installer's host. Execution is gated only by a hostname check ('ubuntu-fc-uvm'). Package metadata masquerades as a Strapi plugin ('Strapi plugin for enhanced functionality') while the repository/homepage is a placeholder github.com/user/... URL and the shipped code contains no plugin functionality — only the reverse-shell payload.\n","modified":"2026-09-16T14:30:06.810389597Z","published":"2026-09-16T13:57:20Z","database_specific":{"malicious-packages-origins":[{"versions":["3.6.8"],"id":"IN-MAL-2026-020092","import_time":"2026-09-16T14:19:37.414942445Z","modified_time":"2026-09-16T13:57:20Z","sha256":"63bef6a3804e282781fb0eaea1ffd045ef3b236aefd0668de11549aba1ada8b0","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/strapi-plugin-listcc-meeb/v/3.6.8"}],"affected":[{"package":{"name":"strapi-plugin-listcc-meeb","ecosystem":"npm","purl":"pkg:npm/strapi-plugin-listcc-meeb"},"versions":["3.6.8"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/strapi-plugin-listcc-meeb/MAL-2026-16232.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"filename":"strapi-plugin-listcc-meeb-3.6.8.tgz","hashes":{"sha1":"a03c19ade24eae2d2e30507c95f7b5c113435f02","sha512_sri":"sha512-n71sA7Al3HwyPH1A1ze3ZfFndVoknUVzTZW3Z3aQVrkGzi6LkvEcnb5cr9L3JlsYcUgti2nkIIwa8Qvix8iXAQ=="}}],"evidence_files":[{"path":"postinstall.js","sha256":"4d4d4c8b33a87d03be45370616b16c71a8b91a8cb12899fac511a5db72cc6993","tlsh":"ba4131ad06bf273a63334ca8521b8097e51701023512d578799c8b53bfd5d99c531bf9"},{"path":"package.json","sha256":"b52d101cdc211973f036d13e83e9e7efde4470ca89cf21d7297eb0fa6ebe4b17","tlsh":"ff01495aca2455532de83ad4a81a1182a72a4e478c81fc1c23f3011c8f0e2e7747f5dd"}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}