Malicious code in tt-help-cli-ycl (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (e6144be61d70f258741e5d4cc1476021f93e3ce82ffa00a3f86189537a1438a6) The package's `tt-help watchdog` subcommand starts a long-running agent that POSTs heartbeats to a remote server (default hardcoded to http://117.71.53.99:17301, referenced in src/lib/constants.js and the README/run-explore examples) and executes commands returned in the response. In WatchdogAgent, syncCommands maps entries from the server's `commands` array into child_process.spawn(command, { shell: true }) via ProcessManager.startCommand, with auto-restart — the remote operator selects arbitrary shell commands to run on the installer's host. Each heartbeat body assembled by _buildHeartbeatBody carries hostname, non-internal IPv4 address, OS platform/release/arch, CPU count, memory, node version, uptime, load average, and the contents of ~/.tt-help.json (server, proxy, browser, userId, tuning fields), POSTed as JSON to ${serverUrl}/api/watchdog/heartbeat at the configured interval (default 15s). In addition, _startUpgradeChecker polls the npm registry every 10 minutes and, when a new version of tt-help-cli-ycl is published, invokes `npm install -g tt-help-cli-ycl@latest` via child_process.exec and re-spawns, so the publisher can push arbitrary new code to every running agent host without user confirmation. The combination of remote-command execution, ongoing host inventory + stored-config exfiltration to a bare-IP destination, and unattended auto-upgrade constitutes a full command-and-control backdoor rather than a legitimate remote-management tool.
AI Analysis
Technical Summary
The tt-help-cli-ycl npm package includes a 'watchdog' subcommand that runs an agent posting a heartbeat with detailed host system information (hostname, IP, OS details, CPU, memory, uptime, load, Node.js version, running processes, and user-specific config file contents) to a remote server at http://117.71.53.99:17301. The server response contains shell commands that the agent executes directly on the host, enabling arbitrary remote code execution. Additionally, the package periodically checks the npm registry every 10 minutes and automatically installs any new version published under the 'latest' tag, allowing the attacker to push updates silently. The communication is unencrypted and uses a hardcoded IP address and port, increasing detection risk but also indicating a persistent backdoor.
Potential Impact
This malicious package enables an attacker to gain persistent, arbitrary remote code execution on any system running the affected versions, potentially leading to full system compromise. The automatic self-updating mechanism allows the attacker to maintain and escalate control without user consent. The exposure of detailed system information to the attacker facilitates targeted attacks and evasion.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately remove the affected versions (=1.4.59, =1.4.60, =1.4.61) of tt-help-cli-ycl from their environments and avoid installing or updating this package. Monitor for any unexpected network connections to suspicious IP addresses such as 117.71.53.99 and investigate any instances of this package. Check vendor advisories or trusted security sources for updates or official fixes.
Malicious code in tt-help-cli-ycl (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (e6144be61d70f258741e5d4cc1476021f93e3ce82ffa00a3f86189537a1438a6) The package's `tt-help watchdog` subcommand starts a long-running agent that POSTs heartbeats to a remote server (default hardcoded to http://117.71.53.99:17301, referenced in src/lib/constants.js and the README/run-explore examples) and executes commands returned in the response. In WatchdogAgent, syncCommands maps entries from the server's `commands` array into child_process.spawn(command, { shell: true }) via ProcessManager.startCommand, with auto-restart — the remote operator selects arbitrary shell commands to run on the installer's host. Each heartbeat body assembled by _buildHeartbeatBody carries hostname, non-internal IPv4 address, OS platform/release/arch, CPU count, memory, node version, uptime, load average, and the contents of ~/.tt-help.json (server, proxy, browser, userId, tuning fields), POSTed as JSON to ${serverUrl}/api/watchdog/heartbeat at the configured interval (default 15s). In addition, _startUpgradeChecker polls the npm registry every 10 minutes and, when a new version of tt-help-cli-ycl is published, invokes `npm install -g tt-help-cli-ycl@latest` via child_process.exec and re-spawns, so the publisher can push arbitrary new code to every running agent host without user confirmation. The combination of remote-command execution, ongoing host inventory + stored-config exfiltration to a bare-IP destination, and unattended auto-upgrade constitutes a full command-and-control backdoor rather than a legitimate remote-management tool.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The tt-help-cli-ycl npm package includes a 'watchdog' subcommand that runs an agent posting a heartbeat with detailed host system information (hostname, IP, OS details, CPU, memory, uptime, load, Node.js version, running processes, and user-specific config file contents) to a remote server at http://117.71.53.99:17301. The server response contains shell commands that the agent executes directly on the host, enabling arbitrary remote code execution. Additionally, the package periodically checks the npm registry every 10 minutes and automatically installs any new version published under the 'latest' tag, allowing the attacker to push updates silently. The communication is unencrypted and uses a hardcoded IP address and port, increasing detection risk but also indicating a persistent backdoor.
Potential Impact
This malicious package enables an attacker to gain persistent, arbitrary remote code execution on any system running the affected versions, potentially leading to full system compromise. The automatic self-updating mechanism allows the attacker to maintain and escalate control without user consent. The exposure of detailed system information to the attacker facilitates targeted attacks and evasion.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately remove the affected versions (=1.4.59, =1.4.60, =1.4.61) of tt-help-cli-ycl from their environments and avoid installing or updating this package. Monitor for any unexpected network connections to suspicious IP addresses such as 117.71.53.99 and investigate any instances of this package. Check vendor advisories or trusted security sources for updates or official fixes.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12488
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a735741bf8831d539154dd9
Added to database: 08/05/2026, 15:31:13 UTC
Last enriched: 08/05/2026, 17:00:47 UTC
Last updated: 09/16/2026, 14:15:57 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.