Malicious code in commandor-cli (npm)
The npm package commandor-cli version 1.0.0 contains malicious code in its postinstall script. This script XOR-decodes a hardcoded URL to download a binary from a personal GitHub repository, writes it to the temporary directory, and executes it detached. On Windows Subsystem for Linux (WSL), it uses a PowerShell command to execute the binary on the Windows host, extending the attack surface. Additionally, the script sends an install beacon with platform information to a hardcoded IP address over unencrypted HTTP. The binary is unsigned and fetched from an untrusted source, and the payload URLs and commands are obfuscated using XOR encoding.
AI Analysis
Technical Summary
The commandor-cli npm package version 1.0.0 includes a postinstall script that performs malicious actions. It XOR-decodes a URL pointing to a GitHub repository hosting a binary executable, downloads this binary to the %TEMP% directory as main.exe, and executes it in a detached process. For users running WSL, the script further decodes a PowerShell command that downloads and executes the same binary on the Windows host, thereby compromising both Linux and Windows environments. The script also constructs an IPv4 address from an array and sends a JSON beacon containing platform details to http://193.70.34.101:20099/vote via plain HTTP. The use of XOR encoding for URLs and commands indicates an attempt to evade detection. The binary lacks any hash or signature verification, increasing the risk of arbitrary code execution. The source repository is unrelated to any legitimate publisher, indicating a supply chain compromise or malicious package upload.
Potential Impact
This malicious package can lead to arbitrary code execution on the host system during installation, affecting both Linux and Windows environments (via WSL). The execution of an unsigned binary from an untrusted source can result in system compromise, data theft, or further malware deployment. The beaconing to a remote IP address over unencrypted HTTP may expose system information to an attacker and facilitate command and control activities. The obfuscation techniques used hinder detection and analysis.
Mitigation Recommendations
Users should immediately uninstall commandor-cli version 1.0.0 and avoid installing this package from untrusted sources. Since no patch or official fix is indicated, users should consider this version compromised and avoid using it. Monitor for any unexpected binaries named main.exe in temporary directories and investigate any suspicious network traffic to IP 193.70.34.101 on port 20099. Use trusted package registries and verify package authenticity before installation.
Malicious code in commandor-cli (npm)
Description
The npm package commandor-cli version 1.0.0 contains malicious code in its postinstall script. This script XOR-decodes a hardcoded URL to download a binary from a personal GitHub repository, writes it to the temporary directory, and executes it detached. On Windows Subsystem for Linux (WSL), it uses a PowerShell command to execute the binary on the Windows host, extending the attack surface. Additionally, the script sends an install beacon with platform information to a hardcoded IP address over unencrypted HTTP. The binary is unsigned and fetched from an untrusted source, and the payload URLs and commands are obfuscated using XOR encoding.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The commandor-cli npm package version 1.0.0 includes a postinstall script that performs malicious actions. It XOR-decodes a URL pointing to a GitHub repository hosting a binary executable, downloads this binary to the %TEMP% directory as main.exe, and executes it in a detached process. For users running WSL, the script further decodes a PowerShell command that downloads and executes the same binary on the Windows host, thereby compromising both Linux and Windows environments. The script also constructs an IPv4 address from an array and sends a JSON beacon containing platform details to http://193.70.34.101:20099/vote via plain HTTP. The use of XOR encoding for URLs and commands indicates an attempt to evade detection. The binary lacks any hash or signature verification, increasing the risk of arbitrary code execution. The source repository is unrelated to any legitimate publisher, indicating a supply chain compromise or malicious package upload.
Potential Impact
This malicious package can lead to arbitrary code execution on the host system during installation, affecting both Linux and Windows environments (via WSL). The execution of an unsigned binary from an untrusted source can result in system compromise, data theft, or further malware deployment. The beaconing to a remote IP address over unencrypted HTTP may expose system information to an attacker and facilitate command and control activities. The obfuscation techniques used hinder detection and analysis.
Mitigation Recommendations
Users should immediately uninstall commandor-cli version 1.0.0 and avoid installing this package from untrusted sources. Since no patch or official fix is indicated, users should consider this version compromised and avoid using it. Monitor for any unexpected binaries named main.exe in temporary directories and investigate any suspicious network traffic to IP 193.70.34.101 on port 20099. Use trusted package registries and verify package authenticity before installation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-14172
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a85b4caacd9273b49252e68
Added to database: 08/19/2026, 13:51:06 UTC
Last enriched: 08/19/2026, 14:50:25 UTC
Last updated: 08/19/2026, 14:50:25 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.