reverse_ssh
reverse_ssh is an open-source Golang reverse shell / reverse SSH tool. In the provided reporting, it was identified as functionality used by malware to establish reverse SSH connections to attacker-controlled endpoints. Tenable Research reported that a malicious npm package, ambar-src, delivered a Linux payload identified as a client of github.com/NHAS/reverse_ssh. The package executed via an npm preinstall script, meaning compromise could occur on installation without importing or running the package directly. The campaign targeted Windows, Linux, and macOS developers, with Linux infections fetching a shell script from x-ya[.]ru that downloaded and executed an ELF binary saved as osa; one Linux payload was specifically identified as an NHAS/reverse_ssh client. Reported Linux-related hashes include the shell script SHA-256 8963568963f770e237bff2b228106e4ce7ebb0a1af0e0cf7b26028bdc8515bc5, a Linux payload SHA-256 83e131a2761d6f3a5636cf329182242a927a618174dd440989dc9286be4edeac, and an NHAS/reverse_ssh payload SHA-256 1e6fa5021db4dd40b571cc4e654a71c22d0f607d13fb8a4a5a46a64060f3071e. Separately, SentinelLABS reported that the China-nexus activity cluster PurpleHaze used a Go-based Windows backdoor named GoReShell that leveraged functionality from the open-source reverse_ssh tool to establish reverse SSH connections to attacker-controlled endpoints. SentinelLABS assessed PurpleHaze with high confidence as China-nexus and loosely linked it to APT15. High-confidence infrastructure and delivery details directly mentioned in the content include x-ya[.]ru as the staging domain in the npm supply-chain campaign.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source Golang reverse shell client deployed on Linux as part of the ambar-src infection chain, enabling remote interactive access/pivoting from compromised developer hosts.
Open-source tool providing reverse SSH capability; its functionality is leveraged by GoReShell to create attacker-controlled reverse SSH access.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.