Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in superacli (npm)

The npm package superacli contained malicious code in plugins/gopass/daemon.js that established an unauthorized WebSocket connection to a hardcoded IP address (92.113.145.178:8768), allowing remote operators to execute arbitrary commands against the user's local gopass password store and exfiltrate decrypted secrets.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any user who installed and ran the superacli package with the gopass daemon command, exposing local password manager access to remote operators.
Ecosystems
Attack vectors
Affected entities
  • superaclinpm package containing malicious gopass daemon code

The superacli npm package contained a backdoor in its gopass daemon plugin that connected to a hardcoded bare IP address (92.113.145.178:8768) using a shared secret for authentication. The daemon would register the local hostname and platform with the remote peer upon connection.

Once connected, the daemon accepted inbound 'command' messages and executed them against the user's local gopass password store using bash spawning, supporting operations like show, insert, delete, sync, and generate. Command output—including decrypted secrets—was returned directly to the remote operator.

The malicious IP address was not a publisher-owned domain but a bare IP, indicating this was a silent relay attack against the installer's most sensitive local secret store. Users who ran the documented gopass daemon command would unknowingly hand remote control of their password manager to whoever controlled that IP address, with no per-installer authentication challenge.

The vulnerability was discovered and credited to the OpenSSF's malicious-packages project.

Indicators of compromise

Packages
  • superacli
IPs
  • 92.113.145.178

Remediation

  • Immediately uninstall the superacli package from all systems
  • Audit all systems where superacli was installed and the gopass daemon was run for unauthorized access or credential exfiltration
  • Rotate all passwords and secrets managed by gopass on affected systems
  • Review network logs for outbound WebSocket connections to 92.113.145.178:8768
  • Use only verified, trusted password manager packages from reputable sources
  • Monitor npm package updates and security advisories for similar malicious packages

Sources

  1. GitHub Advisory GHSA-7g4m-4fmq-259x · GitHub Advisory Database

Cite this entry

"Malicious code in superacli (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 27, 2026; last updated July 27, 2026. https://supplychainattack.org/incident/malicious-code-in-superacli-npm-1l7jta

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in @antv/g-webgl-compute (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g-webgl-compute, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    npmOtherAccount takeoverCompromised packageMalicious commit
  2. containedcritical

    Malicious code in @antv/g2-ssr (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g2-ssr, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    npmAccount takeoverCompromised packageMalicious commit
  3. containedcritical

    Malicious code in @antv/g6-extension-3d (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g6-extension-3d, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    npmOtherAccount takeoverCompromised packageMalicious commit
  4. containedcritical

    Malicious code in @antv/gi-assets-basic (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/gi-assets-basic, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    npmOtherAccount takeoverCompromised packageMalicious commit