MAL-2026-6217

    Dashboard / Malicious Package / MAL-2026-6217

    MAL-2026-6217

    Published: 19 Jun 2026Last Modified: 19 Jun 2026

    Summary: Malicious code in aikaf788812 (npm)

    Details: Source: amazon-inspector (c91950cef6a5f877a4a9bca074501e4c910dc50008d4c8c2623ddc21f08e31f2) Package masquerades as a string-utility library but ships a postinstall backdoor. On `npm install`, scripts/postinstall.js spawns scripts/shell.js as a detached background process (stdio:'ignore', windowsHide:true) that survives the install lifecycle. shell.js attempts multiple reverse-shell methods — a Node net socket piping /bin/sh or powershell, bash /dev/tcp, and a Python socket+subprocess payload — connecting to 114.67.90.67 on ports 3334, 4444, 443, 80, 8080, and 53. It additionally issues an HTTP GET to http://114.67.90.67:8333/ping carrying the installer's hostname, username, cwd, and OS platform/release as query parameters, fingerprinting the victim and confirming compromise. A setInterval keep-alive plus an infinite Python reconnect loop maintain persistent C2 access on the installer's machine.

    Affected packages

    Package

    Name: aikaf788812

    Purl: pkg:npm/aikaf788812

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.3
    MAL-2026-6217 | CVE-DB