MAL-2026-12488

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tt-help-cli-ycl/MAL-2026-12488.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-12488
Published
2026-08-05T12:17:18Z
Modified
2026-08-07T14:49:46Z
Summary
Malicious code in tt-help-cli-ycl (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (e6144be61d70f258741e5d4cc1476021f93e3ce82ffa00a3f86189537a1438a6)

The package's tt-help watchdog subcommand starts a long-running agent that POSTs heartbeats to a remote server (default hardcoded to http://117.71.53.99:17301, referenced in src/lib/constants.js and the README/run-explore examples) and executes commands returned in the response. In WatchdogAgent, syncCommands maps entries from the server's commands array into child_process.spawn(command, { shell: true }) via ProcessManager.startCommand, with auto-restart — the remote operator selects arbitrary shell commands to run on the installer's host. Each heartbeat body assembled by _buildHeartbeatBody carries hostname, non-internal IPv4 address, OS platform/release/arch, CPU count, memory, node version, uptime, load average, and the contents of ~/.tt-help.json (server, proxy, browser, userId, tuning fields), POSTed as JSON to ${serverUrl}/api/watchdog/heartbeat at the configured interval (default 15s). In addition, _startUpgradeChecker polls the npm registry every 10 minutes and, when a new version of tt-help-cli-ycl is published, invokes npm install -g tt-help-cli-ycl@latest via child_process.exec and re-spawns, so the publisher can push arbitrary new code to every running agent host without user confirmation. The combination of remote-command execution, ongoing host inventory + stored-config exfiltration to a bare-IP destination, and unattended auto-upgrade constitutes a full command-and-control backdoor rather than a legitimate remote-management tool.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-014817",
            "import_time": "2026-08-05T13:08:48.762843245Z",
            "modified_time": "2026-08-05T12:56:32Z",
            "sha256": "425b148abb84342912d6e2caf046da7ccf806a32c1b3950a3d41366980fd3eed",
            "source": "amazon-inspector",
            "versions": [
                "1.4.61"
            ]
        },
        {
            "id": "IN-MAL-2026-014793",
            "import_time": "2026-08-05T13:08:46.902424357Z",
            "modified_time": "2026-08-05T12:52:06Z",
            "sha256": "5246f6fbb6e6d46a9a9cab000fb5e2c2f2816831f9df67f64803054c92423963",
            "source": "amazon-inspector",
            "versions": [
                "1.4.59"
            ]
        },
        {
            "id": "IN-MAL-2026-014633",
            "import_time": "2026-08-05T13:08:32.162615831Z",
            "modified_time": "2026-08-05T12:17:18Z",
            "sha256": "dc827d9593cc7d3cb899922b4e5a26de6ae026ca1994165607b9fb63bcf71207",
            "source": "amazon-inspector",
            "versions": [
                "1.4.60"
            ]
        },
        {
            "id": "IN-MAL-2026-015793",
            "import_time": "2026-08-05T16:13:45.719027921Z",
            "modified_time": "2026-08-05T15:41:09Z",
            "sha256": "2b08749c0630d26064b36e3071e5baea85518db047bbbba08354d016de4dc317",
            "source": "amazon-inspector",
            "versions": [
                "1.4.63"
            ]
        },
        {
            "id": "IN-MAL-2026-015790",
            "import_time": "2026-08-05T16:13:45.498283711Z",
            "modified_time": "2026-08-05T15:40:37Z",
            "sha256": "e6144be61d70f258741e5d4cc1476021f93e3ce82ffa00a3f86189537a1438a6",
            "source": "amazon-inspector",
            "versions": [
                "1.4.64"
            ]
        },
        {
            "id": "IN-MAL-2026-016261",
            "import_time": "2026-08-06T13:09:07.945422116Z",
            "modified_time": "2026-08-06T12:55:14Z",
            "sha256": "0dd6259fc4fef46022321a36e47e5fa376b3ea75efd865739972cefe81d39f44",
            "source": "amazon-inspector",
            "versions": [
                "1.4.67"
            ]
        },
        {
            "id": "IN-MAL-2026-016258",
            "import_time": "2026-08-06T13:09:07.632603577Z",
            "modified_time": "2026-08-06T12:54:47Z",
            "sha256": "10e07f1b41f6d7006d567df95e1b0c8d66b0421acc475728775b7202b0100645",
            "source": "amazon-inspector",
            "versions": [
                "1.4.71"
            ]
        },
        {
            "id": "IN-MAL-2026-016255",
            "import_time": "2026-08-06T13:09:07.368667765Z",
            "modified_time": "2026-08-06T12:54:20Z",
            "sha256": "37d7042d1599b8debfbd542ec7e3a1f863a2d0d8ae75776f34b43f0886e0f439",
            "source": "amazon-inspector",
            "versions": [
                "1.4.65"
            ]
        },
        {
            "id": "IN-MAL-2026-016256",
            "import_time": "2026-08-06T13:09:07.458991897Z",
            "modified_time": "2026-08-06T12:54:31Z",
            "sha256": "402f9b1404d216c056fe64795e3b99247cfa3d2e622e639ea7d2e3353c1e2deb",
            "source": "amazon-inspector",
            "versions": [
                "1.4.70"
            ]
        },
        {
            "id": "IN-MAL-2026-016265",
            "import_time": "2026-08-06T13:09:08.397459136Z",
            "modified_time": "2026-08-06T12:55:49Z",
            "sha256": "9847510afa4b965a2dcac10901f9904c43bcf5f2652e51b755ab18509cc20ad5",
            "source": "amazon-inspector",
            "versions": [
                "1.4.66"
            ]
        },
        {
            "id": "IN-MAL-2026-016266",
            "import_time": "2026-08-06T13:09:08.540731744Z",
            "modified_time": "2026-08-06T12:56:00Z",
            "sha256": "be0b9d48edaef660b4d633e0211492e7b5a16c73a04fda03b4111e6975de4f4c",
            "source": "amazon-inspector",
            "versions": [
                "1.4.57"
            ]
        },
        {
            "id": "IN-MAL-2026-016257",
            "import_time": "2026-08-06T13:09:07.54585318Z",
            "modified_time": "2026-08-06T12:54:38Z",
            "sha256": "e8582513a8f8461374843816fddae5c0e10e1bc9b8eec62751a5a93a37dcc598",
            "source": "amazon-inspector",
            "versions": [
                "1.4.73"
            ]
        },
        {
            "id": "IN-MAL-2026-016260",
            "import_time": "2026-08-06T13:09:07.824506707Z",
            "modified_time": "2026-08-06T12:55:04Z",
            "sha256": "ec04b56635a7ef02a3e026f79a1ff0bd91f4b3208b2ebf34d35b66dacd2ad3b8",
            "source": "amazon-inspector",
            "versions": [
                "1.4.62"
            ]
        },
        {
            "id": "IN-MAL-2026-016262",
            "import_time": "2026-08-06T13:09:08.032578342Z",
            "modified_time": "2026-08-06T12:55:22Z",
            "sha256": "a49b203a895b6dc9765e7bca1f48efdc4bd1f51e6ac1c5a85b3a3aefd274e093",
            "source": "amazon-inspector",
            "versions": [
                "1.4.69"
            ]
        },
        {
            "id": "IN-MAL-2026-016259",
            "import_time": "2026-08-06T13:09:07.719135616Z",
            "modified_time": "2026-08-06T12:54:55Z",
            "sha256": "b1a2cabd93a9d96eecf5fd8356a9ef7ad867d758a00844d7852c7acd87871779",
            "source": "amazon-inspector",
            "versions": [
                "1.4.72"
            ]
        },
        {
            "id": "IN-MAL-2026-016263",
            "import_time": "2026-08-06T13:09:08.183971467Z",
            "modified_time": "2026-08-06T12:55:32Z",
            "sha256": "ee3080a4ce6b88ee9bb8dac5c5881b9c3479b0cbf9aa31ad63cbc01c34ebcec4",
            "source": "amazon-inspector",
            "versions": [
                "1.4.58"
            ]
        },
        {
            "id": "IN-MAL-2026-016264",
            "import_time": "2026-08-06T13:09:08.271523493Z",
            "modified_time": "2026-08-06T12:55:39Z",
            "sha256": "f7e11b8aa382aca577ceb5b4b96fb55e893903af9547b7394b21981723b50271",
            "source": "amazon-inspector",
            "versions": [
                "1.4.68"
            ]
        },
        {
            "id": "IN-MAL-2026-016364",
            "import_time": "2026-08-06T14:19:45.341736184Z",
            "modified_time": "2026-08-06T13:10:34Z",
            "sha256": "a6a7892e662701e9afec65b057e5e62c0271ba4e9486fd93355d54940caaa77a",
            "source": "amazon-inspector",
            "versions": [
                "1.4.74"
            ]
        },
        {
            "id": "IN-MAL-2026-017079",
            "import_time": "2026-08-07T14:26:54.308294612Z",
            "modified_time": "2026-08-07T13:41:08Z",
            "sha256": "53e5ac496bfe78550d62897473d919a91ca99b9d2094e3b047154a1b06b3ae24",
            "source": "amazon-inspector",
            "versions": [
                "1.4.78"
            ]
        },
        {
            "id": "IN-MAL-2026-017078",
            "import_time": "2026-08-07T14:26:54.250984304Z",
            "modified_time": "2026-08-07T13:41:00Z",
            "sha256": "d48ae50449c449b787861aaa24f700d9d2e934dbf414b9d184f2af80b1bd2105",
            "source": "amazon-inspector",
            "versions": [
                "1.4.75"
            ]
        },
        {
            "id": "IN-MAL-2026-017080",
            "import_time": "2026-08-07T14:26:54.371045548Z",
            "modified_time": "2026-08-07T13:41:16Z",
            "sha256": "0ebb6712b5224c449113cdc08e378e3bdde0d4fa85f4a88a712a8b0dacf34dc2",
            "source": "amazon-inspector",
            "versions": [
                "1.4.76"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / tt-help-cli-ycl

Package

Name
tt-help-cli-ycl
View open source insights on deps.dev
Purl
pkg:npm/tt-help-cli-ycl

Affected ranges

Affected versions

1.*
1.4.57
1.4.58
1.4.59
1.4.60
1.4.61
1.4.62
1.4.63
1.4.64
1.4.65
1.4.66
1.4.67
1.4.68
1.4.69
1.4.70
1.4.71
1.4.72
1.4.73
1.4.74
1.4.75
1.4.76
1.4.78

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "src/watchdog/process-manager.js",
            "sha256": "2793e929cce7d05d3d13c28b85698fcc3db19cd79429ad40942284d6f9f3cc4b",
            "tlsh": "a512b41958fd01577ab300141beba1162aa1a50faa09fe587dfd9b680fc847405f2be8"
        },
        {
            "path": "scripts/run-explore.sh",
            "sha256": "8bb4d832911102a6ff59b54747a1f5786a77a0c3fbe8c1861395a9f6b93d1b8e",
            "tlsh": "2e9175c37d4d8a309265cae26892212ef267425b19097dd4f0a1d12b3c5cfbaa73d5a3"
        },
        {
            "path": "src/watchdog/agent.js",
            "sha256": "827b95a667158573376a44554fe8971deb96146d4774c68674af904490318ec3",
            "tlsh": "70d193098aff00666876115a6f2700032971a20f1d87ed0cbfad47cd8fd9a3c85a5fb5"
        },
        {
            "path": "src/watchdog/upgrader.js",
            "sha256": "33fab057b3a6c40a1029282d285543009874bb0dd68ec87a0f2e5bddf74c5447",
            "tlsh": "515130c929f7613182b2b22da61f9015377681432b4eee11ba9d47106f4a824a5b3fcc"
        }
    ],
    "package_integrity": [
        {
            "filename": "tt-help-cli-ycl-1.4.61.tgz",
            "hashes": {
                "sha1": "b3c9e9704661f6175ab4449585c0500cfa69dc7e",
                "sha512_sri": "sha512-s4cB/UfGLIS0T1uIfEZ7zcB0w3zqvMTxBX774HldzBaPU0mK+hP8pO6dIcGMbjLlF14ayUawiMvUAzx9t2eJug=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tt-help-cli-ycl/MAL-2026-12488.json"