habingeer @2.1.6
Vulnerability report · Last retrieved from osv.dev July 23, 2026 at 9:18 AM UTC
OSV ID
MAL-2026-10995
Ecosystem
npm
Summary
package.json declares postinstall: node test.js , which auto-runs on npm install and invokes two functions from index.js. The first recursively walks the install directory for id.json (Solana keypair), config.toml / Config.toml , env , and .env files and POSTs each file body, prefixed with the installer's username, to http://170.205.31.203:3000/api/v1. The second fetches an SSH public key from http://170.205.31.203:3001/api/ssh-key and, on Linux, appends it to ~/.ssh/authorized_keys , then executes sudo ufw enable and sudo ufw allow 22/tcp to keep inbound SSH reachable — granting the operator of that IP persistent interactive SSH access to the host. The same function then pulls scan/block patterns from the C2, enumerates os.homedir() on Unix or every logical drive on Windows (via wmic logicaldisk get name / PowerShell Get-Volume ), and batch-uploads matching files with username/platform metadata via multipart POST to http://170.205.31.203:3001/api/v1. All three behaviors fire on install with no user interaction.
Source: amazon-inspector (716d1a3d9969396f8ca204c03d403552bb4a990c1bfdb4a2ab05dff5afb93748)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.