malware npm

centralogger

discovered 2026-04-14

centralogger is identified in the SafeDep analysis "Malicious dom-utils-lite npm SSH Backdoor via Supabase". dom-utils-lite and centralogger on npm inject attacker SSH keys into ~/.ssh/authorized_keys and exfiltrate server metadata to Supabase-hosted C2 infrastructure, granting persistent remote access.

Threat types

persistence data_exfiltration c2_agent

Malicious versions

  • 1.0.5
  • 1.0.6
  • 1.0.7
  • 1.0.8
  • 1.0.9

Campaigns

Indicators

Techniques

Read the full analysis →