npm · Malicious package advisory
Malwarestrapi-plugin-ccsuc-meeb
GHSA-g2q3-qp84-8cj7
Malicious code in strapi-plugin-ccsuc-meeb (npm)
Details
**Severity:** Critical
**Affected versions:** `= 3.6.8`
## Source: amazon-inspector (8fb6207f1b4ec4d94c724583a5f32b85f68d203e1a9e6372705b410efbf9173a)
The package's postinstall lifecycle script (postinstall.js, wired via scripts.postinstall in package.json) checks the installer's hostname against a hardcoded allowlist value ('ubuntu-fc-uvm') and, on match, spawns /bin/bash with a reverse-shell one-liner opening an interactive TCP shell to 14.225.210.85:80. The script uses child_process.exec, includes retry logic and a 60-second timeout, and runs automatically on `npm install`. The hostname gate indicates a targeted-dropper shape aimed at specific installer environments; on matching hosts the operator obtains full interactive command execution on the installer's machine.
---
Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a03f98a1b88f3ad29d120e41e5d5e14f25d25979/osv/malicious/npm/strapi-plugin-ccsuc-meeb/MAL-2026-16209.json))
**References:**
- https://github.com/ossf/malicious-packages/blob/a03f98a1b88f3ad29d120e41e5d5e14f25d25979/osv/malicious/npm/strapi-plugin-ccsuc-meeb/MAL-2026-16209.json
- https://www.npmjs.com/package/strapi-plugin-ccsuc-meeb/v/3.6.8
- https://github.com/advisories/GHSA-g2q3-qp84-8cj7Compromised versions (1)
- = 3.6.8
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.