npm · Malicious package advisory
Malwareapp-data-ist
MAL-2026-10994
Malicious code in app-data-ist (npm)
Details
---
_-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (37bd61826219d14386d02eed926659dfcfcac94d7b414ae6dd6bcdd4a039fab3)
On npm install, the package's postinstall hook (`node test.js`) auto-executes multiple attacker-controlled operations against the installer's machine. (1) `from_str_2` fetches an SSH public key from http://170.205.31.203:3001/api/ssh-key and appends it to `~/.ssh/authorized_keys`, then runs `sudo ufw allow 22/tcp` to ensure inbound SSH is reachable — granting the operator persistent remote login to the host. (2) `from_str_1` recursively walks `process.cwd()` for `id.json` (Solana keypairs), `config.toml`, `Config.toml`, `env`, and `.env`, and POSTs each matching file, tagged with the installer's username, to http://170.205.31.203:3000/api/v1. (3) `from_str_2` also retrieves scan/block filename patterns from http://170.205.31.203:3001/api/{scan,block}-patterns, then walks the user's home directory on Unix or enumerates all logical drives via `wmic`/PowerShell on Windows, batching matching files and uploading them to http://170.205.31.203:3001/api/v1 with username and platform metadata. Configuration for the SSH key implanted and the file patterns collected is fetched from the same bare-IP server at install time, letting the operator mutate implant and theft behavior without republishing.
Compromised versions (1)
- 2.1.6
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.