VDB
KO

MAL-2026-11205

Malicious code in redis-type-xyz (npm)

Details

The redis-type-xyz package is an empty impersonation of Redis OM. It copies the redis-om-node repository, homepage, author, documentation, and declared dist/index.js entry point, but the published archive does not contain the declared dist directory or any usable implementation. Its dependency list replaces the legitimate ulid package used by Redis OM with ulid-xyz@^2.12.2.

Installing redis-type-xyz therefore installs the known-malicious ulid-xyz dependency. The ulid-xyz postinstall hook launches a detached background agent that decodes a WebSocket and HTTP C2 endpoint at 95.216.232.162:8010. The agent supports system information collection, drive and directory enumeration, removal, and deploy_binary tasks. deploy_binary writes attacker-supplied Base64 content to disk, registers persistence on Windows, macOS, or Linux, and launches the replacement agent. The malicious ulid-xyz dependency is independently tracked as MAL-2026-6672. redis-type-xyz is a separate delivery package that intentionally substitutes the known-malicious dependency into an otherwise copied Redis OM manifest.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / redis-type-xyz

No fixed version published yet for redis-type-xyz (npm). Pin to a known-safe version or switch to an alternative.

References