MAL-2026-16209
Malicious code in strapi-plugin-ccsuc-meeb (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (8fb6207f1b4ec4d94c724583a5f32b85f68d203e1a9e6372705b410efbf9173a) The package's postinstall lifecycle script (postinstall.js, wired via scripts.postinstall in package.json) checks the installer's hostname against a hardcoded allowlist value ('ubuntu-fc-uvm') and, on match, spawns /bin/bash with a reverse-shell one-liner opening an interactive TCP shell to 14.225.210.85:80. The script uses child_process.exec, includes retry logic and a 60-second timeout, and runs automatically on `npm install`. The hostname gate indicates a targeted-dropper shape aimed at specific installer environments; on matching hosts the operator obtains full interactive command execution on the installer's machine.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for strapi-plugin-ccsuc-meeb (npm). Pin to a known-safe version or switch to an alternative.