Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in sm-admin (npm)

Malicious npm package sm-admin versions 99.0.0 and 99.0.1 contained preinstall and postinstall lifecycle scripts that made plain-HTTP GET requests to attacker-controlled endpoints, exfiltrating installer IP addresses and probing for private registry usage.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any developer or CI/CD system that installed sm-admin@99.0.0 or sm-admin@99.0.1 from npm would execute the malicious preinstall/postinstall scripts.
Ecosystems
Attack vectors
Affected entities
  • sm-admin · 99.0.0, 99.0.1

The npm package sm-admin versions 99.0.0 and 99.0.1 were identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package contained preinstall and postinstall lifecycle scripts that issued unencrypted HTTP GET requests to attacker-controlled bare IPv4 endpoints (http://16.192.173.5/sm-admin/pre and http://16.192.173.5/sm-admin/post).\n\nInstallation of the package caused the installer's host to contact these endpoints, revealing the installer's source IP address to the attacker and potentially disclosing whether the internal name 'sm-admin' resolved on the target machine. The elevated version number (99.0.0/99.0.1) and callback pattern are characteristic of a dependency-confusion attack probing for private registry usage.\n\nThe attacker-controlled endpoint was unauthenticated, meaning the response body served to the lifecycle scripts could be modified at any time to deliver additional malicious payloads. Any developer or automated system that installed these versions would have executed the malicious scripts during package installation.

Indicators of compromise

Packages
  • sm-admin@99.0.0
  • sm-admin@99.0.1
IPs
  • 16.192.173.5

Remediation

  • Immediately uninstall sm-admin@99.0.0 and sm-admin@99.0.1 from all environments
  • Audit npm package.lock or yarn.lock files for any installations of affected versions
  • Review network logs for outbound HTTP connections to 16.192.173.5 from the time of installation
  • Regenerate any credentials or secrets that may have been exposed on machines that installed the package
  • Use npm audit to check for dependency-confusion vulnerabilities in private package names
  • Consider using npm package integrity verification and private registry authentication

Sources

  1. GitHub Advisory GHSA-g8wg-mh5v-wf2r · GitHub Advisory Database

Cite this entry

"Malicious code in sm-admin (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 24, 2026; last updated August 24, 2026. https://supplychainattack.org/incident/malicious-code-in-sm-admin-npm-ciwhrv

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in amundi-compare (npm)

    Malicious npm package amundi-compare@999.9.12 published at an inflated version number as a dependency-confusion attack. The package executes a preinstall hook that exfiltrates system and project metadata via HTTP, HTTPS, and DNS covert channels to da51rv0hb2uc72tg4gvgdepinjcallbk1.oast.fun.

    npmCompromised packageDependency confusion
  2. resolvedcritical

    Malicious code in fund-calculator (npm)

    Malicious npm package fund-calculator (version 999.9.12) contained a preinstall script that collected system and project metadata from installers and exfiltrated it via HTTP, HTTPS, and DNS to a hardcoded callback domain. The package was designed as a dependency-confusion attack to shadow an internal private package.

    npmCompromised packageDependency confusion
  3. activecritical

    Malicious code in sm-billing-form (npm)

    Malicious npm package sm-billing-form (versions 99.0.0 and 99.0.1) contains preinstall and postinstall lifecycle scripts that execute curl commands to a hardcoded IP address (16.192.173.5) over cleartext HTTP, exfiltrating install environment details. The high version number and behavior pattern indicate a dependency-confusion attack targeting internal packages of the same name.

    npmCompromised packageDependency confusion
  4. containedcritical

    Malicious code in sm-cart (npm)

    Malicious npm package sm-cart (versions 99.0.0 and 99.0.1) uses dependency confusion and preinstall/postinstall scripts to beacon to a hardcoded IP address (16.192.173.5) over plain HTTP, disclosing the installing host's public IP and successful installation. The package is designed to win resolution when an organization has an internal package with the same name.

    npmDependency confusionCompromised package