MAL-2026-12488
Malicious code in tt-help-cli-ycl (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (e6144be61d70f258741e5d4cc1476021f93e3ce82ffa00a3f86189537a1438a6) The package's `tt-help watchdog` subcommand starts a long-running agent that POSTs heartbeats to a remote server (default hardcoded to http://117.71.53.99:17301, referenced in src/lib/constants.js and the README/run-explore examples) and executes commands returned in the response. In WatchdogAgent, syncCommands maps entries from the server's `commands` array into child_process.spawn(command, { shell: true }) via ProcessManager.startCommand, with auto-restart — the remote operator selects arbitrary shell commands to run on the installer's host. Each heartbeat body assembled by _buildHeartbeatBody carries hostname, non-internal IPv4 address, OS platform/release/arch, CPU count, memory, node version, uptime, load average, and the contents of ~/.tt-help.json (server, proxy, browser, userId, tuning fields), POSTed as JSON to ${serverUrl}/api/watchdog/heartbeat at the configured interval (default 15s). In addition, _startUpgradeChecker polls the npm registry every 10 minutes and, when a new version of tt-help-cli-ycl is published, invokes `npm install -g tt-help-cli-ycl@latest` via child_process.exec and re-spawns, so the publisher can push arbitrary new code to every running agent host without user confirmation. The combination of remote-command execution, ongoing host inventory + stored-config exfiltration to a bare-IP destination, and unattended auto-upgrade constitutes a full command-and-control backdoor rather than a legitimate remote-management tool.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for tt-help-cli-ycl (npm). Pin to a known-safe version or switch to an alternative.
References
- https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.61 [PACKAGE]
- https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.59 [PACKAGE]
- https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.60 [PACKAGE]
- https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.63 [PACKAGE]
- https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.64 [PACKAGE]
- https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.67 [PACKAGE]
- https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.71 [PACKAGE]
- https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.65 [PACKAGE]
- https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.70 [PACKAGE]
- https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.66 [PACKAGE]
- https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.57 [PACKAGE]
- https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.73 [PACKAGE]
- https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.62 [PACKAGE]
- https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.69 [PACKAGE]
- https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.72 [PACKAGE]
- https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.58 [PACKAGE]
- https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.68 [PACKAGE]
- https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.74 [PACKAGE]
- https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.78 [PACKAGE]
- https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.75 [PACKAGE]
- https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.76 [PACKAGE]