LWA-2026-0208 confirmed malware

@cryptobaby/cryptopapi@6.6.7

Malicious code in @cryptobaby/cryptopapi (npm)

T1027 · Obfuscated Files or Information

Analysis

This package is a Solana wallet drainer (a de-obfuscated variant of the same code). On import the main entry (src/esm/index.js, with a CJS twin at src/cjs/index.cjs) walks parent directories to find a .env file and reads PRIVATE_KEY and RPC_ENDPOINT, rebuilding a Solana Keypair. It fetches the SOL/USD price from api[.]coingecko[.]com/api/v3/simple/price?ids=solana and, when the wallet's USD value exceeds a $1000 threshold, signs and submits a VersionedTransaction that drains the full balance (less fee and a 0.001 SOL reserve) to the hardcoded destination 7y6drvHexdLjKDMeWPRwTdQt1NUd7tAZNmeZNkoAYcKk. C2/IOC: drain destination Solana address 7y6drvHexdLjKDMeWPRwTdQt1NUd7tAZNmeZNkoAYcKk.

analyzed by
Leitwacht
first seen
May 27, 2026, 04:18 AM
analyzed
May 27, 2026, 04:36 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.