@cryptobaby/cryptopapi@6.6.7
Malicious code in @cryptobaby/cryptopapi (npm)
Analysis
This package is a Solana wallet drainer (a de-obfuscated variant of the same code). On import the main entry (src/esm/index.js, with a CJS twin at src/cjs/index.cjs) walks parent directories to find a .env file and reads PRIVATE_KEY and RPC_ENDPOINT, rebuilding a Solana Keypair. It fetches the SOL/USD price from api[.]coingecko[.]com/api/v3/simple/price?ids=solana and, when the wallet's USD value exceeds a $1000 threshold, signs and submits a VersionedTransaction that drains the full balance (less fee and a 0.001 SOL reserve) to the hardcoded destination 7y6drvHexdLjKDMeWPRwTdQt1NUd7tAZNmeZNkoAYcKk. C2/IOC: drain destination Solana address 7y6drvHexdLjKDMeWPRwTdQt1NUd7tAZNmeZNkoAYcKk.
- analyzed by
- Leitwacht
- first seen
- May 27, 2026, 04:18 AM
- analyzed
- May 27, 2026, 04:36 AM
Related advisories
- @cryptobaby/cryptopapi@6.6.6 same package
- vitest-preview-pro@10.0.7
- @coralxyz/anchor@0.30.2
- hardhat-cap@2.21.1
- dolyame-ui-draghoc@35.8.1
- dolyame-ui-tablemobile@35.8.1
- txrand@1.0.6
- khanbmnxls@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.