npm

app-data-ist @2.1.6

Vulnerability report · Last retrieved from osv.dev July 23, 2026 at 9:18 AM UTC

Malicious

OSV ID

MAL-2026-10994

Ecosystem

npm

Summary

On npm install, the package's postinstall hook ( node test.js ) auto-executes multiple attacker-controlled operations against the installer's machine. (1) from_str_2 fetches an SSH public key from http://170.205.31.203:3001/api/ssh-key and appends it to ~/.ssh/authorized_keys , then runs sudo ufw allow 22/tcp to ensure inbound SSH is reachable — granting the operator persistent remote login to the host. (2) from_str_1 recursively walks process.cwd() for id.json (Solana keypairs), config.toml , Config.toml , env , and .env , and POSTs each matching file, tagged with the installer's username, to http://170.205.31.203:3000/api/v1. (3) from_str_2 also retrieves scan/block filename patterns from http://170.205.31.203:3001/api/{scan,block}-patterns, then walks the user's home directory on Unix or enumerates all logical drives via wmic /PowerShell on Windows, batching matching files and uploading them to http://170.205.31.203:3001/api/v1 with username and platform metadata. Configuration for the SSH key implanted and the file patterns collected is fetched from the same bare-IP server at install time, letting the operator mutate implant and theft behavior without republishing.

Source: amazon-inspector (37bd61826219d14386d02eed926659dfcfcac94d7b414ae6dd6bcdd4a039fab3)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.