strapi-plugin-plsresh-meeb@3.6.8
Vulnerability report · Last retrieved from osv.dev September 16, 2026 at 3:27 AM UTC
OSV ID
MAL-2026-16181
Ecosystem
npm
Summary
The package's postinstall lifecycle script runs a bash reverse shell that opens a TCP connection to the hardcoded host 14.225.210.85 on port 443 and binds an interactive shell to that socket, granting whoever operates that endpoint full interactive command execution on the installer's host. Execution is automatic on npm install via scripts.postinstall, requires no user action, and also writes a marker file under /tmp to confirm the callback. The package's own description self-labels as a reverse shell payload for Strapi.
Source: amazon-inspector (ae27e46ab1160942d8d569f2237b9890a5f0a2cac36171ced091678c2a876c44)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.