Skip to main content

Malicious code in system-performance-helper (npm)

0
Critical
Published: 08/19/2026 (08/19/2026, 01:16:23 UTC)
Source: GCVE Database
Product: system-performance-helper

Description

The npm package 'system-performance-helper' version 1.0.0 contains malicious code that executes a reverse shell backdoor during installation. The postinstall script opens a TCP connection to a hardcoded IP and port, spawning an OS shell that allows full remote code execution on the host. The package's advertised functionality is a cover, as the actual payload runs silently and fails quietly without providing the claimed monitoring features.

Affected software

npmghsa
system-performance-helper
Affected versions
=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/19/2026, 14:43:04 UTC

Technical Analysis

The 'system-performance-helper' npm package (version 1.0.0) includes a postinstall hook that executes 'node install.js'. This script attempts to open a TCP socket to a hardcoded IP address and port (currently set to 'YOUR_PUBLIC_IP' and 4444), spawning a shell process (/bin/sh on Unix or cmd.exe on Windows). The shell's stdin, stdout, and stderr are piped through the socket with auto-reconnect and keep-alive features, effectively creating a reverse shell backdoor. Although the hardcoded IP is a placeholder that prevents actual callback by default, any republishing of the package with a real IP would enable full remote code execution on any system installing the package. The package's index.js exports functions related to system load and memory as a cover, but these are not connected to the malicious postinstall behavior.

Potential Impact

If the placeholder IP is replaced with a real address, installing this package would result in a reverse shell connection to an attacker-controlled server, granting full remote code execution on the victim's machine. This compromises the confidentiality, integrity, and availability of the host system. Even without modification, the presence of such a backdoor in the package poses a significant supply chain risk if republished or used as a dependency.

Mitigation Recommendations

No official patch or fix is currently available. Users should avoid installing or using 'system-performance-helper' version 1.0.0. Verify package authenticity and source before installation, and consider removing this package if already installed. Monitor for republished versions with the placeholder replaced by a real IP address. Since this is not a cloud service, remediation depends on user action to avoid or remove the malicious package.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-14194
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6a85b4c8acd9273b49252899

Added to database: 08/19/2026, 13:51:04 UTC

Last enriched: 08/19/2026, 14:43:04 UTC

Last updated: 10/02/2026, 13:52:41 UTC

Views: 52

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses