VDB
Sign up

MAL-2026-16209

Malicious code in strapi-plugin-ccsuc-meeb (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (8fb6207f1b4ec4d94c724583a5f32b85f68d203e1a9e6372705b410efbf9173a) The package's postinstall lifecycle script (postinstall.js, wired via scripts.postinstall in package.json) checks the installer's hostname against a hardcoded allowlist value ('ubuntu-fc-uvm') and, on match, spawns /bin/bash with a reverse-shell one-liner opening an interactive TCP shell to 14.225.210.85:80. The script uses child_process.exec, includes retry logic and a 60-second timeout, and runs automatically on `npm install`. The hostname gate indicates a targeted-dropper shape aimed at specific installer environments; on matching hosts the operator obtains full interactive command execution on the installer's machine.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/strapi-plugin-ccsuc-meeb

No fixed version published yet for strapi-plugin-ccsuc-meeb (npm). Pin to a known-safe version or switch to an alternative.

References