MAL-2026-11000

    Dashboard / Malicious Package / MAL-2026-11000

    MAL-2026-11000

    Published: 22 Jul 2026Last Modified: 23 Jul 2026

    Summary: Malicious code in application-util (npm)

    Details: Source: amazon-inspector (07fa5354b40e3efac6ff8738892aa26cb710e6aff3caca516f563502ef4a4d43) On npm install, scripts.postinstall runs test.js which performs three attacker-beneficial actions against the installer's host. (1) Backdoor: fetches an SSH public key from http://170.205.31.203:3001/api/ssh-key, appends it to ~/.ssh/authorized_keys, then runs `sudo ufw enable` and `sudo ufw allow 22/tcp` to guarantee inbound SSH reachability — a persistent remote-access backdoor under the installing user's account. (2) Credential theft: recursively scans process.cwd() for id.json (Solana keypair), config.toml, Config.toml, env, and.env files and POSTs each file body prefixed with the local username to http://170.205.31.203:3000/api/v1. (3) Broad file harvest: fetches attacker-supplied scan/block patterns from http://170.205.31.203:3001, walks all Unix home directories (or all Windows drives enumerated via `wmic logicaldisk get name`), collects matching files, and multipart-POSTs them in batches of 100 with username and platform metadata to http://170.205.31.203:3001/api/v1. Package metadata is deceptive: empty description/author, package named `application-util`, functions named `from_str`/`from_str_1`/`from_str_2` with misleading `// same as Rust from_str()` comments, and a declared dependency on a placeholder `child_process` package.

    Affected packages

    Package

    Name: application-util

    Purl: pkg:npm/application-util

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    2.1.6
    MAL-2026-11000 | CVE-DB