Skip to content

Add OSV reports for 3 malicious npm packages - #1353

Merged
elitsa-gosst merged 1 commit into
ossf:mainfrom
KunalSin9h:srm0rgan-jonconway-malicious-npm
Jul 13, 2026
Merged

Add OSV reports for 3 malicious npm packages#1353
elitsa-gosst merged 1 commit into
ossf:mainfrom
KunalSin9h:srm0rgan-jonconway-malicious-npm

Conversation

@KunalSin9h

@KunalSin9h KunalSin9h commented Jul 7, 2026

Copy link
Copy Markdown
Contributor

srm0rgan — fake "Paperclip" VPS-maintenance adapters. Same author already has three merged reports: MAL-2026-6755 (paperclip2), MAL-2026-6756 (vps-maintenance), MAL-2026-6757 (vps-maintenance-paperclip-adapter). These two complete the campaign:

  • vps-adapter-core — plants an attacker SSH key in authorized_keys, writes /etc/cron.d persistence, exfiltrates cloud/SSH/CI credentials over /dev/tcp, and opens reverse shells to 185.112.147.174 (30s keep-alive).
  • paperclip-host-utils — payload cycles across versions 1.0.2–1.0.7: SSH-key+cron backdoor, an HTTP credential dumper disguised as an npm audit POST, and a reverse shell. Same C2.

jon_conway

  • express-mongo-limit — typosquat of express-mongo-sanitize; exfiltrates process.env, fetches + executes remote JS (RCE backdoor), hijacks crypto clipboard addresses, and emails desktop screenshots to the attacker.

- vps-adapter-core, paperclip-host-utils: 'srm0rgan' campaign of fake
  Paperclip VPS-maintenance adapters (siblings already reported as
  MAL-2026-6755, MAL-2026-6756, MAL-2026-6757). Install-time SSH-key
  backdoor, cron persistence, cloud/SSH/CI credential exfiltration and
  reverse shells to C2 185.112.147.174.
- express-mongo-limit: 'jon_conway', typosquat of express-mongo-sanitize.
  postinstall env exfiltration, remote-code-execution backdoor, crypto
  clipboard hijacker and screenshot spyware.

Signed-off-by: Kunal Singh <kunalsin9h@gmail.com>
@elitsa-gosst
elitsa-gosst merged commit 8147305 into ossf:main Jul 13, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants