-= Per source details. Do not edit below this line.=-
package.json declares postinstall: node test.js, which auto-runs on npm install and invokes two functions from index.js. The first recursively walks the install directory for id.json (Solana keypair), config.toml/Config.toml, env, and .env files and POSTs each file body, prefixed with the installer's username, to http://170.205.31.203:3000/api/v1. The second fetches an SSH public key from http://170.205.31.203:3001/api/ssh-key and, on Linux, appends it to ~/.ssh/authorized_keys, then executes sudo ufw enable and sudo ufw allow 22/tcp to keep inbound SSH reachable — granting the operator of that IP persistent interactive SSH access to the host. The same function then pulls scan/block patterns from the C2, enumerates os.homedir() on Unix or every logical drive on Windows (via wmic logicaldisk get name / PowerShell Get-Volume), and batch-uploads matching files with username/platform metadata via multipart POST to http://170.205.31.203:3001/api/v1. All three behaviors fire on install with no user interaction.
2.1.6Exploitability
AV:NAC:LPR:NUI:NScope
S:CImpact
C:HI:HA:H10.0/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H