-= Per source details. Do not edit below this line.=-
The package's tt-help watchdog subcommand starts a long-running agent that POSTs heartbeats to a remote server (default hardcoded to http://117.71.53.99:17301, referenced in src/lib/constants.js and the README/run-explore examples) and executes commands returned in the response. In WatchdogAgent, syncCommands maps entries from the server's commands array into child_process.spawn(command, { shell: true }) via ProcessManager.startCommand, with auto-restart — the remote operator selects arbitrary shell commands to run on the installer's host. Each heartbeat body assembled by _buildHeartbeatBody carries hostname, non-internal IPv4 address, OS platform/release/arch, CPU count, memory, node version, uptime, load average, and the contents of ~/.tt-help.json (server, proxy, browser, userId, tuning fields), POSTed as JSON to ${serverUrl}/api/watchdog/heartbeat at the configured interval (default 15s). In addition, startUpgradeChecker polls the npm registry every 10 minutes and, when a new version of tt-help-cli-ycl is published, invokes npm install -g tt-help-cli-ycl@latest via childprocess.exec and re-spawns, so the publisher can push arbitrary new code to every running agent host without user confirmation. The combination of remote-command execution, ongoing host inventory + stored-config exfiltration to a bare-IP destination, and unattended auto-upgrade constitutes a full command-and-control backdoor rather than a legitimate remote-management tool.
{
"malicious-packages-origins": [
{
"import_time": "2026-08-05T13:08:48.762843245Z",
"sha256": "425b148abb84342912d6e2caf046da7ccf806a32c1b3950a3d41366980fd3eed",
"modified_time": "2026-08-05T12:56:32Z",
"id": "IN-MAL-2026-014817",
"versions": [
"1.4.61"
],
"source": "amazon-inspector"
},
{
"import_time": "2026-08-05T13:08:46.902424357Z",
"modified_time": "2026-08-05T12:52:06Z",
"sha256": "5246f6fbb6e6d46a9a9cab000fb5e2c2f2816831f9df67f64803054c92423963",
"id": "IN-MAL-2026-014793",
"versions": [
"1.4.59"
],
"source": "amazon-inspector"
},
{
"source": "amazon-inspector",
"modified_time": "2026-08-05T12:17:18Z",
"sha256": "dc827d9593cc7d3cb899922b4e5a26de6ae026ca1994165607b9fb63bcf71207",
"id": "IN-MAL-2026-014633",
"versions": [
"1.4.60"
],
"import_time": "2026-08-05T13:08:32.162615831Z"
},
{
"import_time": "2026-08-05T16:13:45.719027921Z",
"modified_time": "2026-08-05T15:41:09Z",
"sha256": "2b08749c0630d26064b36e3071e5baea85518db047bbbba08354d016de4dc317",
"id": "IN-MAL-2026-015793",
"versions": [
"1.4.63"
],
"source": "amazon-inspector"
},
{
"source": "amazon-inspector",
"modified_time": "2026-08-05T15:40:37Z",
"sha256": "e6144be61d70f258741e5d4cc1476021f93e3ce82ffa00a3f86189537a1438a6",
"id": "IN-MAL-2026-015790",
"versions": [
"1.4.64"
],
"import_time": "2026-08-05T16:13:45.498283711Z"
}
]
}[
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
}
]
{
"package_integrity": [
{
"hashes": {
"sha512_sri": "sha512-s4cB/UfGLIS0T1uIfEZ7zcB0w3zqvMTxBX774HldzBaPU0mK+hP8pO6dIcGMbjLlF14ayUawiMvUAzx9t2eJug==",
"sha1": "b3c9e9704661f6175ab4449585c0500cfa69dc7e"
},
"filename": "tt-help-cli-ycl-1.4.61.tgz"
}
],
"evidence_files": [
{
"path": "src/watchdog/process-manager.js",
"sha256": "2793e929cce7d05d3d13c28b85698fcc3db19cd79429ad40942284d6f9f3cc4b",
"tlsh": "a512b41958fd01577ab300141beba1162aa1a50faa09fe587dfd9b680fc847405f2be8"
},
{
"path": "scripts/run-explore.sh",
"sha256": "8bb4d832911102a6ff59b54747a1f5786a77a0c3fbe8c1861395a9f6b93d1b8e",
"tlsh": "2e9175c37d4d8a309265cae26892212ef267425b19097dd4f0a1d12b3c5cfbaa73d5a3"
},
{
"path": "src/watchdog/agent.js",
"sha256": "827b95a667158573376a44554fe8971deb96146d4774c68674af904490318ec3",
"tlsh": "70d193098aff00666876115a6f2700032971a20f1d87ed0cbfad47cd8fd9a3c85a5fb5"
},
{
"path": "src/watchdog/upgrader.js",
"sha256": "33fab057b3a6c40a1029282d285543009874bb0dd68ec87a0f2e5bddf74c5447",
"tlsh": "515130c929f7613182b2b22da61f9015377681432b4eee11ba9d47106f4a824a5b3fcc"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tt-help-cli-ycl/MAL-2026-12488.json"