Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-16191 confirms this npm version as malicious. postinstall.js is registered as both the npm postinstall hook and the package main. On install it polls os.hostname() every 3 seconds and, when the hostname matches the hardcoded value 'ubuntu-fc-uvm', spawns 'bash -i' with stdio bound to /dev/tcp/14.225.210.85/80, yielding an interactive reverse shell on the installer's host to the operator of that endpoint...
This report applies to strapi-plugin-uicc-meeb@3.6.8.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.