Threats Tagged 'mal-2026-15572'
View all threats tagged with 'mal-2026-15572'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'mal-2026-15572'
Click on any threat for detailed analysis and mitigation recommendations
Malicious code in grafeno-payments (npm) 0 --- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (7af58da84956e51749cbb96923f12264cfdee76456b5010b526599b7da2c0caa) On `npm install`, package.json's preinstall hook (`node preinstall.js || true`) auto-runs a script that (1) enumerates process.env for keys matching AWS|TOKEN|KEY|SECRET|PASS|API, concatenates them with the machine's hostname and username, base64-encodes the blob, and exfiltrates it via `curl` GET to http://216.126.236.46/r.php over plain HTTP; and (2) on non-Windows hosts invokes `bash -i` with a /dev/tcp redirection to 216.126.236.46:4444, giving the remote endpoint an interactive shell on the installer's machine. The `|| true` suffix suppresses errors so `npm install` reports success while the payload runs. The package's stated payments purpose is a cover story; the shipped preinstall behavior is credential theft plus full-host remote code execution against the installer. Join the discussion | GCVE Database | 08/29/2026, 23:10:48 UTC Added: 08/29/2026, 23:30:06 UTC |
Showing 1 to 1 of 1 result