MAL-2026-16194
Malicious code in strapi-plugin-yesccresh-meeb (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (4b4fa4d6fa3f37bcc5179aecbcb365bc73d94ac1cb799ac4f93fa4702292b493) package.json declares postinstall: node postinstall.js, which unconditionally spawns bash with stdio redirected to /dev/tcp/14.225.210.85/443, giving the remote endpoint interactive command execution as the installing user on every npm install. The script includes a reconnect loop that re-establishes the shell on disconnect, providing persistence for the duration of the process. No user action, configuration, or runtime invocation is required for the callback to fire.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for strapi-plugin-yesccresh-meeb (npm). Pin to a known-safe version or switch to an alternative.