Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Malicious npm Package Disguised as Advcash Integration Trigg...

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
937
Company Posts That Month
27
Language
English
Hacker News Points
-
Post removed?
No
Summary

A malicious npm package, disguised as an Advcash payment integration, has been discovered by the Socket Research Team, which executes a reverse shell during a successful transaction, giving attackers remote access to servers. The package, named `@naderabdi/merchant-advcash`, masquerades as a legitimate payment processing tool, complete with functions for creating payment orders, validating incoming requests, and updating transaction statuses, while secretly embedding a reverse shell that triggers specifically during transaction success events. This stealthy approach to malware evades detection by delaying execution until runtime, targeting production environments where real transactions occur. The package's sophisticated design, including input validation and SHA-256 hashing, provides a credible façade that misleads developers into integrating it into their systems, thus maximizing the attacker's reach. After the discovery, the package was reported and removed from npm to prevent further exploitation.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.