Malicious code in system-performance-helper (npm)
Description
The npm package 'system-performance-helper' version 1.0.0 contains malicious code that executes a reverse shell backdoor during installation. The postinstall script opens a TCP connection to a hardcoded IP and port, spawning an OS shell that allows full remote code execution on the host. The package's advertised functionality is a cover, as the actual payload runs silently and fails quietly without providing the claimed monitoring features.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'system-performance-helper' npm package (version 1.0.0) includes a postinstall hook that executes 'node install.js'. This script attempts to open a TCP socket to a hardcoded IP address and port (currently set to 'YOUR_PUBLIC_IP' and 4444), spawning a shell process (/bin/sh on Unix or cmd.exe on Windows). The shell's stdin, stdout, and stderr are piped through the socket with auto-reconnect and keep-alive features, effectively creating a reverse shell backdoor. Although the hardcoded IP is a placeholder that prevents actual callback by default, any republishing of the package with a real IP would enable full remote code execution on any system installing the package. The package's index.js exports functions related to system load and memory as a cover, but these are not connected to the malicious postinstall behavior.
Potential Impact
If the placeholder IP is replaced with a real address, installing this package would result in a reverse shell connection to an attacker-controlled server, granting full remote code execution on the victim's machine. This compromises the confidentiality, integrity, and availability of the host system. Even without modification, the presence of such a backdoor in the package poses a significant supply chain risk if republished or used as a dependency.
Mitigation Recommendations
No official patch or fix is currently available. Users should avoid installing or using 'system-performance-helper' version 1.0.0. Verify package authenticity and source before installation, and consider removing this package if already installed. Monitor for republished versions with the placeholder replaced by a real IP address. Since this is not a cloud service, remediation depends on user action to avoid or remove the malicious package.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-14194
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a85b4c8acd9273b49252899
Added to database: 08/19/2026, 13:51:04 UTC
Last enriched: 08/19/2026, 14:43:04 UTC
Last updated: 10/02/2026, 13:52:41 UTC
Views: 52
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.