Breaking News: “Shai-Hulud: Here We Go Again” – “tensorlake” npm Package Hit With Malware
Read the Report
Rethink cloud security in an AI-driven era. Watch our webinar with James Berthoty and Chris Lindsey
Save your spot

Malware Detected: Reverse Shell Without JavaScript Files in npm

Malware Detected paperclip2

OX Research found paperclip2, an npm package with no JavaScript files, hiding a reverse shell in its config file — and two related packages carrying the same payload

Overview

The OX Research team found a malicious npm package called paperclip2. It contains only a package.json file. No JavaScript. 

A one-liner inside its postinstall script spawns a reverse shell. The absence of any JavaScript files appears designed to evade malware scanners that look for executable code rather than configuration files.

Two related packages use the same reverse shell one-liner in their postinstall scripts:

  • vps-maintenance
  • vps-maintenance-paperclip-adapter

Combined, the three packages have been downloaded 1,049 times per week.

Immediate Actions:

  1. Remove the affected packages
  2. Manually inspect and delete any entries referencing these packages in package lock files and package.json files
  3. Check for unknown and suspicious processes using port 7007 and kill the underlying process

Technical Analysis

image

The malware consists only of a package.json file, which contains an embedded postinstall script one-liner:

image

The malware connects to 185[.]112[.]147[.]174 on port 7007, and spawns a reverse shell.

image

Malicious Packages

Package nameAffected versions
paperclip2Any
vps-maintenanceAny
vps-maintenance-paperclip-adapterAny

Tags:

OX cloud 1

Active AI Defense. Complete Cloud Visibility.

Your agents hold identities you never issued. See what they touch, in real time.

Meet OX Cloud
Frame 2085668530

Subscribe to Our Newsletter

Stay updated with the latest SaaS insights, tips, and news delivered straight to your inbox.

Group 1261154229