@coralxyz/anchor@0.30.2
Malicious code in @coralxyz/anchor (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059.001 · PowerShellT1105 · Ingress Tool TransferT1027 · Obfuscated Files or Information
Analysis
The postinstall hook (scripts/postinstall.js) is an obfuscated Windows-only dropper. On Windows it downloads hxxps://files[.]catbox[.]moe/9bppy2[.]zip to %TEMP%/anc_<random>.zip, extracts it with powershell.exe Expand-Archive, then locates the first .exe in the extracted directory and launches it as a detached process before deleting the zip. The package name impersonates the Anchor Solana framework (@coralxyz/anchor vs the real @coral-xyz/anchor).
- analyzed by
- Leitwacht
- first seen
- Aug 7, 2026, 07:37 PM
- analyzed
- Aug 7, 2026, 07:37 PM
Related advisories
- @rbx-ts/services@1.6.0
- wormgpt-cli@1.0.1
- dolyame-ui-swiper@35.7.7
- stellarfixer@1.0.0
- approval-guardian@1.0.8
- warp-drive-internal-tooling@99.9.9
- mcp-audit-sync-internal@99.9.9
- native-hello-plugin@1.2.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.