@devcarron/clob@2.73.0
Malicious code in @devcarron/clob (npm)
Analysis
The package is a dropper: its postinstall hook uses child_process (execSync/spawn) to download a ~4MB Windows executable (clob2.0.exe) via IPFS gateways (Pinata and Cloudflare), reading a PINATA_GATEWAY_TOKEN from the environment, and drops the binary into %LOCALAPPDATA%. The npm package serves only to deliver an external binary payload.
- analyzed by
- Leitwacht
- first seen
- May 27, 2026, 05:22 AM
- analyzed
- May 27, 2026, 05:22 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.