Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in app-data-ist (npm)

0
Critical
Published: 07/22/2026 (07/22/2026, 20:25:42 UTC)
Source: GCVE Database
Product: app-data-ist

Description

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (37bd61826219d14386d02eed926659dfcfcac94d7b414ae6dd6bcdd4a039fab3) On npm install, the package's postinstall hook (`node test.js`) auto-executes multiple attacker-controlled operations against the installer's machine. (1) `from_str_2` fetches an SSH public key from http://170.205.31.203:3001/api/ssh-key and appends it to `~/.ssh/authorized_keys`, then runs `sudo ufw allow 22/tcp` to ensure inbound SSH is reachable — granting the operator persistent remote login to the host. (2) `from_str_1` recursively walks `process.cwd()` for `id.json` (Solana keypairs), `config.toml`, `Config.toml`, `env`, and `.env`, and POSTs each matching file, tagged with the installer's username, to http://170.205.31.203:3000/api/v1. (3) `from_str_2` also retrieves scan/block filename patterns from http://170.205.31.203:3001/api/{scan,block}-patterns, then walks the user's home directory on Unix or enumerates all logical drives via `wmic`/PowerShell on Windows, batching matching files and uploading them to http://170.205.31.203:3001/api/v1 with username and platform metadata. Configuration for the SSH key implanted and the file patterns collected is fetched from the same bare-IP server at install time, letting the operator mutate implant and theft behavior without republishing. ## Source: ghsa-malware (b2131462e0e7e1b71f5f47819883b4d004ac90ac91377a7e7482ed2b5faa21b7) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Affected software

npmghsa
app-data-ist
Affected versions
=2.1.6

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/22/2026, 23:50:19 UTC

Technical Analysis

The 'app-data-ist' npm package version 2.1.6 contains a postinstall script that automatically executes malicious operations on the installer's machine. It downloads an SSH public key from a remote IP and appends it to '~/.ssh/authorized_keys', then opens SSH access via 'sudo ufw allow 22/tcp', granting persistent remote login. The script recursively searches the current working directory for files like 'id.json' (Solana keypairs), 'config.toml', and environment files, exfiltrating them with user metadata to the attacker's server. It also fetches file scan and block patterns from the attacker to identify and upload additional files from the user's home directory or all logical drives on Windows, sending these to the attacker's endpoint with platform and username information. The implant's behavior is dynamically controlled by configuration fetched at install time, allowing the attacker to change the malicious actions without republishing the package.

Potential Impact

This malicious package compromises the installer's machine by granting the attacker persistent SSH access, enabling remote control. It also results in the theft of sensitive files including cryptographic keypairs and environment configurations, potentially exposing credentials and secrets. The dynamic configuration mechanism allows ongoing modification of the attacker's data collection and implant behavior, increasing the threat's persistence and adaptability.

Mitigation Recommendations

No official patch or remediation is currently available. Users should avoid installing the 'app-data-ist' package version 2.1.6 from npm. If already installed, inspect and remove the malicious SSH key from '~/.ssh/authorized_keys' and revoke any unauthorized firewall rules allowing SSH access. Review and secure any exposed sensitive files. Monitor for suspicious network connections to the indicated IP addresses. Check the vendor advisory or npm security advisories for updates or official fixes.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-10994
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a6151149c2644c7f8da4fd5

Added to database: 07/22/2026, 23:24:04 UTC

Last enriched: 07/22/2026, 23:50:19 UTC

Last updated: 08/27/2026, 18:55:44 UTC

Views: 33

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses