0

My vps is running Ubuntu 16.04. Recently, I have found a lot of failed ssh connections in /var/log/auth.log. I have enabled fail2ban and disabled password authentication. Now, there are some unnamed processes which use 100 % CPU load in my VPS. Before, I have installed nodejs and npm package using root. Below is output of htop

htop column: PPID SessionID PID username ...

The process 1550 is a child of process 1, it forks many unnamed processes. I think they are bitcoin miners or malwares.
Does anyone know about them ? I'm suspicious of vulnerability in a nodejs package. Thank all !

kietheros
  • 101

0 Answers0