stillm4ddpocs-demo-gadgetnpm
Advisory published Updated
stillm4ddpocs-demo-gadget is a confirmed malicious npm package (MAL-2026-14361) that opens a backdoor for remote access (malicious versions 999.9.10, 999.9.12, 999.9.20). Do not install it — remove it immediately and rotate any exposed credentials.
Malicious code in stillm4ddpocs-demo-gadget (npm)
What this malware does
On npm install, the declared preinstall script runs index.js, which collects the installer's hostname, OS username, home directory, cwd (INIT_CWD of the consuming project), local IPv4 address, egress public IP (fetched from api.ipify.org, icanhazip.com, and ifconfig.me), DNS resolver information, and the parent project's package.json fields (name, author, repository, homepage). The collected data is transmitted to the hardcoded third-party callback host da51rv0hb2uc72tg4gvgdepinjcalbk1.oast.fun via both DNS queries (hex-chunked subdomain lookups) and HTTPS POST to /poc/<uuid>. The package name and version pattern are consistent with a dependency-confusion lure targeting an internal scope; the beacon fires automatically at install time without any caller opt-in. Although the author metadata self-labels this as an authorized proof-of-concept, the code performs the full exploitation shape (auto-exec on install, installer-identifier collection, egress to an attacker-controlled callback) against anyone who resolves this public name.
The OpenSSF Package Analysis project identified 'stillm4ddpocs-demo-gadget' @ 999.9.10 (npm) as malicious.
It is considered malicious because:
- The package communicates with a domain associated with malicious activity.
Malicious versions
Indicators of compromise (SHA-256)
Detection & response playbook
Backdoor / remote accessFind it
Search your lockfiles and build artifacts for stillm4ddpocs-demo-gadget (3 malicious versions).
If you installed it — respond
stillm4ddpocs-demo-gadget establishes remote access, so treat any host that installed it as fully compromised. Isolate the machine, remove the package, rotate all credentials it could reach, and rebuild from a trusted image rather than cleaning in place — a backdoor may have planted additional persistence.
Did it already run?
If stillm4ddpocs-demo-gadget was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.
Frequently asked questions
Campaign
References
Credits
- Amazon Inspector · finder
- OpenSSF: Package Analysis · finder
Detect & block this
O3 blocks stillm4ddpocs-demo-gadget-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the C2 callback and severs the channel.