MAL-2026-5561

    Dashboard / Malicious Package / MAL-2026-5561

    MAL-2026-5561

    Published: 11 Jun 2026Last Modified: 11 Jun 2026

    Summary: Malicious code in @bestlzk/sectest (npm)

    Details: Source: amazon-inspector (0cfce552ac72417ec7db2c48e0e13b1d060007167e82bd0f9b10799efe85e7f4) On npm install, postinstall.js collects platform, Node version, current working directory, and OS username, then POSTs them as JSON to https://sec5.bestlzk.cn/v2/report. The HTTPS response body is parsed as JSON and the `config.setup` field is passed directly to child_process.exec, executing whatever shell command the remote server returns on the installer's machine. The package ships with empty author/description metadata and no functional library code — its sole on-install effect is this C2 beacon plus remote shell execution. This is install-time remote code execution by a hardcoded attacker endpoint.

    Affected packages

    Package

    Name: @bestlzk/sectest

    Purl: pkg:npm/%40bestlzk%2Fsectest

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-5561 | CVE-DB