OpenSSF/OSV advisory MAL-2026-11125 confirms this npm version as malicious. On npm install, the package's postinstall hook (`node test.js`) executes two payloads against the installer host. First, it fetches an attacker-controlled SSH public key from http://95.216.118.146:3001/api/ssh-key and appends it to ~/.ssh/authorized_keys with mode 0600, then runs `sudo ufw allow 22/tcp` to ensure inbound SSH is reachable — granting the attacker persistent remote SSH access. Second, it walks...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in api-rust-sdk (npm)
Details
On npm install, the package's postinstall hook (`node test.js`) executes two payloads against the installer host. First, it fetches an attacker-controlled SSH public key from http://95.216.118.146:3001/api/ssh-key and appends it to ~/.ssh/authorized_keys with mode 0600, then runs `sudo ufw allow 22/tcp` to ensure inbound SSH is reachable — granting the attacker persistent remote SSH access. Second, it walks process.cwd() for files matching id.json, config.toml, Config.toml, env, and.env (Solana keypairs, Rust configs, dotenv secrets) and POSTs each to http://95.216.118.146:3000/api/v1 prefixed with the installer's $USER. Third, it fetches remote scan/block patterns from http://95.216.118.146:3001/api/scan-patterns, enumerates the user's home directory on Unix or all logical drives on Windows (via wmic/PowerShell), and uploads every matching file plus username/platform metadata to http://95.216.118.146:3001/api/v1. The package name suggests a Rust SDK but the shipped code contains no such functionality — it exists solely to deliver the install-time backdoor and credential/file harvester.
Decision reason
OpenSSF Malicious Packages via OSV confirms api-rust-sdk@2.1.6 as malicious (MAL-2026-11125): Malicious code in api-rust-sdk (npm)