-= Per source details. Do not edit below this line.=-
On npm install, scripts.postinstall runs test.js which performs three attacker-beneficial actions against the installer's host. (1) Backdoor: fetches an SSH public key from http://170.205.31.203:3001/api/ssh-key, appends it to ~/.ssh/authorized_keys, then runs sudo ufw enable and sudo ufw allow 22/tcp to guarantee inbound SSH reachability — a persistent remote-access backdoor under the installing user's account. (2) Credential theft: recursively scans process.cwd() for id.json (Solana keypair), config.toml, Config.toml, env, and.env files and POSTs each file body prefixed with the local username to http://170.205.31.203:3000/api/v1. (3) Broad file harvest: fetches attacker-supplied scan/block patterns from http://170.205.31.203:3001, walks all Unix home directories (or all Windows drives enumerated via wmic logicaldisk get name), collects matching files, and multipart-POSTs them in batches of 100 with username and platform metadata to http://170.205.31.203:3001/api/v1. Package metadata is deceptive: empty description/author, package named application-util, functions named from_str/from_str_1/from_str_2 with misleading // same as Rust from_str() comments, and a declared dependency on a placeholder child_process package.
{
"malicious-packages-origins": [
{
"import_time": "2026-07-22T20:59:17.177036641Z",
"source": "amazon-inspector",
"sha256": "07fa5354b40e3efac6ff8738892aa26cb710e6aff3caca516f563502ef4a4d43",
"versions": [
"2.1.6"
],
"id": "IN-MAL-2026-010856",
"modified_time": "2026-07-22T20:40:28Z"
}
]
}{
"evidence_files": [
{
"tlsh": "ef02934ca6fb2a2183b371ac468f1415b59ac0033949cd81b2cc97546f8f93d65f6ede",
"sha256": "d986a2e0a9eb3fc3781e166ff6b700e0d38249a6c9649982243c3754671f42d9",
"path": "index.js"
},
{
"tlsh": "32f0ed27ce198ea318f135a8287c4a27f6d1932f0100880f35bd261c4fb7237408af1e",
"sha256": "e0d2753f1c1d84dc8f6585d7678c455f0d54df7771dce99956f114fb0ee73e30",
"path": "package.json"
}
],
"package_integrity": [
{
"filename": "application-util-2.1.6.tgz",
"hashes": {
"sha1": "3d053237f6f4da9e004146416426fe3cb161e431",
"sha512_sri": "sha512-xaW8T7WW+RbCCT4ZnvGz9DP66JJyVwEbELVkxyw0dN9EGjs6B0+/kLKOsUYnp3l7cDtXHQReAlIrabvYJpGenA=="
}
}
]
}
[
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
}
]
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/application-util/MAL-2026-11000.json"