LWA-2026-10797 MAL-2026-13629 ↗ confirmed malware

@coralxyz/anchor@0.30.2

Malicious code in @coralxyz/anchor (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059.001 · PowerShellT1105 · Ingress Tool TransferT1027 · Obfuscated Files or Information

Analysis

The postinstall hook (scripts/postinstall.js) is an obfuscated Windows-only dropper. On Windows it downloads hxxps://files[.]catbox[.]moe/9bppy2[.]zip to %TEMP%/anc_<random>.zip, extracts it with powershell.exe Expand-Archive, then locates the first .exe in the extracted directory and launches it as a detached process before deleting the zip. The package name impersonates the Anchor Solana framework (@coralxyz/anchor vs the real @coral-xyz/anchor).

analyzed by
Leitwacht
first seen
Aug 7, 2026, 07:37 PM
analyzed
Aug 7, 2026, 07:37 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.