Malicious code in sm-payment (npm)
The npm package sm-payment version 99.0.1 contains malicious preinstall and postinstall lifecycle scripts that contact a hardcoded bare IP address (http://16.192.173.5) over plain HTTP during installation. The behavior is consistent with reconnaissance beacons for dependency-confusion or namesquatting attacks.
- Disclosed
- Last updated
- Blast radius
- All npm users who installed sm-payment version 99.0.1
- Ecosystems
- Attack vectors
- Affected entities
- sm-payment · 99.0.1
The npm package sm-payment version 99.0.1 was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package declares preinstall and postinstall lifecycle scripts that automatically execute curl commands to contact a hardcoded bare IP address (http://16.192.173.5/sm-payment/pre and /post) over plain HTTP whenever the package is installed.
The package has no documented build or native-addon functionality that would justify contacting an external IP at install time. The callbacks fire unsolicited on every installation, signaling to the operator of the endpoint that the installer's host has executed the package. This behavior pattern—bare IP, plain HTTP, unrelated to package function, and dual preinstall/postinstall execution—is consistent with reconnaissance beacons used in dependency-confusion or namesquatting attacks.
The OpenSSF Package Analysis project confirmed the package executes commands associated with malicious behavior. The incident was disclosed on 2026-08-24 via GitHub Security Advisory GHSA-mxq2-g955-f593.
Indicators of compromise
- Packages
- sm-payment@99.0.1
- IPs
- 16.192.173.5
Remediation
- Immediately uninstall sm-payment version 99.0.1 from all affected systems
- Audit npm install logs to identify hosts that installed this package
- Review network traffic from affected hosts for connections to 16.192.173.5
- Use npm audit to scan for this package in dependency trees
- Consider blocking the IP address 16.192.173.5 at network perimeter
- Update package.json to remove sm-payment or use a verified alternative if the package is required
Sources
- GitHub Advisory GHSA-mxq2-g955-f593 · GitHub Advisory Database
Cite this entry
"Malicious code in sm-payment (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 24, 2026; last updated August 24, 2026. https://supplychainattack.org/incident/malicious-code-in-sm-payment-npm-7ykb0q
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in amundi-compare (npm)
Malicious npm package amundi-compare@999.9.12 published at an inflated version number as a dependency-confusion attack. The package executes a preinstall hook that exfiltrates system and project metadata via HTTP, HTTPS, and DNS covert channels to da51rv0hb2uc72tg4gvgdepinjcallbk1.oast.fun.
npmCompromised packageDependency confusion - resolvedcritical
Malicious code in fund-calculator (npm)
Malicious npm package fund-calculator (version 999.9.12) contained a preinstall script that collected system and project metadata from installers and exfiltrated it via HTTP, HTTPS, and DNS to a hardcoded callback domain. The package was designed as a dependency-confusion attack to shadow an internal private package.
npmCompromised packageDependency confusion - activecritical
Malicious code in sm-billing-form (npm)
Malicious npm package sm-billing-form (versions 99.0.0 and 99.0.1) contains preinstall and postinstall lifecycle scripts that execute curl commands to a hardcoded IP address (16.192.173.5) over cleartext HTTP, exfiltrating install environment details. The high version number and behavior pattern indicate a dependency-confusion attack targeting internal packages of the same name.
npmCompromised packageDependency confusion - containedcritical
Malicious code in sm-cart (npm)
Malicious npm package sm-cart (versions 99.0.0 and 99.0.1) uses dependency confusion and preinstall/postinstall scripts to beacon to a hardcoded IP address (16.192.173.5) over plain HTTP, disclosing the installing host's public IP and successful installation. The package is designed to win resolution when an organization has an internal package with the same name.
npmDependency confusionCompromised package