python-bitcoinlib@1.0.2
Malicious code in python-bitcoinlib (npm)
Analysis
The postinstall hook (postinstall.js) runs automatically on install. It collects the hostname, username, and current timestamp, then reads credential and wallet files from the user's home directory — .env, .env.local, .env.production, .npmrc, .aws/credentials, .ssh/id_rsa, .ssh/id_ed25519, .ssh/id_ecdsa, .config/solana/id.json, and .ethereum/keystore — and recursively scans all hidden directories for files whose names match wallet, key, secret, seed, mnemonic, keystore, or private, or that end in .json or .pem. All collected file contents are POSTed as a JSON payload to hxxps://webhook[.]site/5c5ad6cb-62df-4ea5-9dfb-2c447920ddc4 over HTTPS. This exfiltrates the installer's credentials, SSH private keys, and cryptocurrency wallet keys.
- analyzed by
- Leitwacht
- first seen
- Aug 5, 2026, 02:05 AM
- analyzed
- Aug 5, 2026, 02:06 AM
Related advisories
- simple-date-formatter-new-6@1.0.0
- simple-date-formatter-new-3@1.0.0
- simple-date-formatter-util-13@1.0.0
- simple-date-formatter-util-11@1.0.0
- simple-date-formatter-util-10@1.0.0
- simple-date-formatter-util-9@1.0.0
- simple-date-formatter-util-6@1.0.0
- approval-guardian@1.0.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.