npm · Malicious package advisory
Malwarestrapi-plugin-maylog-meeb
GHSA-p65g-47hv-5mfm
Malicious code in strapi-plugin-maylog-meeb (npm)
Details
**Severity:** Critical **Affected versions:** `= 3.6.8` ## Source: amazon-inspector (8d714c1585f058d5ac528832398ffe2d0035fd8b60e97e461cdfa8e1533e851c) The package's postinstall.js lifecycle script executes automatically on `npm install` and spawns a python3 reverse shell that connects to the hardcoded remote endpoint 14.225.210.85:80 and attaches an interactive `sh` PTY to the socket, giving the operator of that endpoint full shell access to the installer's host. Prior to the connect, the script collects host identifiers (os.hostname(), os.userInfo().username, process.pid) and writes them to /tmp/postinstall-revshell.log; those identifiers are also exposed to the remote endpoint once the shell attaches. The script retries on failure. The package name and description masquerade as a Strapi audit-log plugin; no functionality in the tarball corresponds to that stated purpose. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/77e1abe54c807a94ef54fde706a23385c94d9e9b/osv/malicious/npm/strapi-plugin-maylog-meeb/MAL-2026-16233.json)) **References:** - https://github.com/ossf/malicious-packages/blob/77e1abe54c807a94ef54fde706a23385c94d9e9b/osv/malicious/npm/strapi-plugin-maylog-meeb/MAL-2026-16233.json - https://www.npmjs.com/package/strapi-plugin-maylog-meeb/v/3.6.8 - https://github.com/advisories/GHSA-p65g-47hv-5mfm
Compromised versions (1)
- = 3.6.8
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.