npm · Malicious package advisory
Malwarehabingeer
GHSA-g3mp-7q55-8g3r
Malicious code in habingeer (npm)
Details
**Severity:** Critical **Affected versions:** `= 2.1.6` ## Source: amazon-inspector (716d1a3d9969396f8ca204c03d403552bb4a990c1bfdb4a2ab05dff5afb93748) package.json declares `postinstall: node test.js`, which auto-runs on `npm install` and invokes two functions from index.js. The first recursively walks the install directory for `id.json` (Solana keypair), `config.toml`/`Config.toml`, `env`, and `.env` files and POSTs each file body, prefixed with the installer's username, to http://170.205.31.203:3000/api/v1. The second fetches an SSH public key from http://170.205.31.203:3001/api/ssh-key and, on Linux, appends it to `~/.ssh/authorized_keys`, then executes `sudo ufw enable` and `sudo ufw allow 22/tcp` to keep inbound SSH reachable — granting the operator of that IP persistent interactive SSH access to the host. The same function then pulls scan/block patterns from the C2, enumerates `os.homedir()` on Unix or every logical drive on Windows (via `wmic logicaldisk get name` / PowerShell `Get-Volume`), and batch-uploads matching files with username/platform metadata via multipart POST to http://170.205.31.203:3001/api/v1. All three behaviors fire on install with no user interaction. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a3d01e3a56cf4ba9e9e1ec313d2e65f53302eb61/osv/malicious/npm/habingeer/MAL-2026-10995.json)) **References:** - https://github.com/ossf/malicious-packages/blob/a3d01e3a56cf4ba9e9e1ec313d2e65f53302eb61/osv/malicious/npm/habingeer/MAL-2026-10995.json - https://www.npmjs.com/package/habingeer/v/2.1.6 - https://github.com/advisories/GHSA-g3mp-7q55-8g3r
Compromised versions (1)
- = 2.1.6
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.