Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in @junyoung-kim/reins (npm)

The npm package @junyoung-kim/reins contained malicious code that establishes a bidirectional WebSocket connection to a hardcoded remote relay endpoint, enabling interactive shell execution on affected hosts. The package can also install itself as a systemd auto-start service for persistence across reboots.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any host running the @junyoung-kim/reins CLI tool; potential for persistent remote shell access via systemd auto-start service installation.
Ecosystems
Attack vectors
Affected entities
  • @junyoung-kim/reinsnpm package containing malicious code

The @junyoung-kim/reins npm package contained embedded malicious functionality that spawns a local pseudo-terminal via node-pty and bridges it to a hardcoded WebSocket endpoint at wss://juny-api.kr/relay. Pairing is coordinated through https://arv.juny-api.kr, with the pairing secret loaded from parent-directory .env files, expanding the trust boundary beyond the package's own directory.\n\nAny party with access to the relay endpoint or a valid pairing token can obtain interactive shell execution on the host running the CLI. The malicious code also includes PATH modifications in dist/cli.mjs consistent with installing shims for the CLI and node-pty runtime, and can install itself as a systemd auto-start service to maintain persistence across system reboots.\n\nThe malicious package was identified through static analysis and reported by the OpenSSF's malicious-packages project.

Indicators of compromise

Packages
  • @junyoung-kim/reins
Domains
  • juny-api.kr
  • arv.juny-api.kr

Remediation

  • Immediately uninstall @junyoung-kim/reins from all systems
  • Audit systems for any systemd services installed by the package and remove them
  • Check parent-directory .env files for exposed pairing secrets and rotate any credentials that may have been compromised
  • Review system logs for evidence of remote shell access via the relay endpoint
  • Scan for any installed shims or PATH modifications in the CLI and node-pty runtime directories
  • Update npm dependencies and verify package integrity

Sources

  1. GitHub Advisory GHSA-785q-v8jw-hfj2 · GitHub Advisory Database

Cite this entry

"Malicious code in @junyoung-kim/reins (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 7, 2026; last updated August 7, 2026. https://supplychainattack.org/incident/malicious-code-in-junyoung-kim-reins-npm-p16t8b

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in pfp-forms-sme-loan (npm)

    The npm package pfp-forms-sme-loan contains malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under well1.site. Any system that imported this package should be considered compromised.

    npmCompromised packageMalicious commit
  2. activecritical

    Malware in anthropic-setup

    The npm package anthropic-setup contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  3. resolvedcritical

    Malicious code in epic-sso (npm)

    The npm package epic-sso was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.

    npmCompromised package
  4. containedcritical

    Malware in bnpl-blocks-independent-bnpl-search

    The npm package bnpl-blocks-independent-bnpl-search contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised.

    npmCompromised package