LWA-2026-10083 MAL-2026-12113 ↗ confirmed malware

python-bitcoinlib@1.0.2

Malicious code in python-bitcoinlib (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1552.004 · Private KeysT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web Service

Analysis

The postinstall hook (postinstall.js) runs automatically on install. It collects the hostname, username, and current timestamp, then reads credential and wallet files from the user's home directory — .env, .env.local, .env.production, .npmrc, .aws/credentials, .ssh/id_rsa, .ssh/id_ed25519, .ssh/id_ecdsa, .config/solana/id.json, and .ethereum/keystore — and recursively scans all hidden directories for files whose names match wallet, key, secret, seed, mnemonic, keystore, or private, or that end in .json or .pem. All collected file contents are POSTed as a JSON payload to hxxps://webhook[.]site/5c5ad6cb-62df-4ea5-9dfb-2c447920ddc4 over HTTPS. This exfiltrates the installer's credentials, SSH private keys, and cryptocurrency wallet keys.

analyzed by
Leitwacht
first seen
Aug 5, 2026, 02:05 AM
analyzed
Aug 5, 2026, 02:06 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.