LWA-2026-0228 MAL-2026-4347 ↗ confirmed malware

@devcarron/clob@2.73.0

Malicious code in @devcarron/clob (npm)

Analysis

The package is a dropper: its postinstall hook uses child_process (execSync/spawn) to download a ~4MB Windows executable (clob2.0.exe) via IPFS gateways (Pinata and Cloudflare), reading a PINATA_GATEWAY_TOKEN from the environment, and drops the binary into %LOCALAPPDATA%. The npm package serves only to deliver an external binary payload.

analyzed by
Leitwacht
first seen
May 27, 2026, 05:22 AM
analyzed
May 27, 2026, 05:22 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.