VYPR

npm · Malicious package advisory

Malware

habingeer

MAL-2026-10995

Malicious code in habingeer (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (716d1a3d9969396f8ca204c03d403552bb4a990c1bfdb4a2ab05dff5afb93748)
package.json declares `postinstall: node test.js`, which auto-runs on `npm install` and invokes two functions from index.js. The first recursively walks the install directory for `id.json` (Solana keypair), `config.toml`/`Config.toml`, `env`, and `.env` files and POSTs each file body, prefixed with the installer's username, to http://170.205.31.203:3000/api/v1. The second fetches an SSH public key from http://170.205.31.203:3001/api/ssh-key and, on Linux, appends it to `~/.ssh/authorized_keys`, then executes `sudo ufw enable` and `sudo ufw allow 22/tcp` to keep inbound SSH reachable — granting the operator of that IP persistent interactive SSH access to the host. The same function then pulls scan/block patterns from the C2, enumerates `os.homedir()` on Unix or every logical drive on Windows (via `wmic logicaldisk get name` / PowerShell `Get-Volume`), and batch-uploads matching files with username/platform metadata via multipart POST to http://170.205.31.203:3001/api/v1. All three behaviors fire on install with no user interaction.

Compromised versions (1)

  • 2.1.6

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.