boring-vault@1.0.0
Malicious code in boring-vault (npm)
Analysis
The preinstall and postinstall hooks both run index.js, which harvests the installer's credentials and posts them to a remote endpoint. On install it scans every environment variable whose name matches KEY, TOKEN, SECRET, PASS, PRIVATE, MNEMONIC, RPC, AWS, GITHUB, NPM, KUBE, VAULT, AUTH, PGP, GPG, SEED or WALLET and captures their values; reads ~/.npmrc and ~/.gitconfig; and lists the contents of ~/.ssh, ~/.foundry/keystores, ~/.config/hardhat and ~/.config/gcloud. All of this (hostname, username, cwd, env secrets, npm/git config, wallet keystore and cloud credential directory listings) is POSTed as JSON to hxxps://webhook[.]site/326b0891-2093-4800-a4c1-686ce3e07b09. The hook swallows all errors so installs never fail. The package name mirrors the Boring Vault DeFi protocol and the payload specifically targets crypto wallet keystores and cloud/SSH credentials.
- analyzed by
- Leitwacht
- first seen
- Aug 11, 2026, 06:08 AM
- analyzed
- Aug 11, 2026, 06:08 AM
Related advisories
- camelot-ammv2-core@1.0.0
- move-bcs-codec@1.0.0
- python-bitcoinlib@1.0.2
- simple-date-formatter-new-6@1.0.0
- simple-date-formatter-new-3@1.0.0
- simple-date-formatter-util-13@1.0.0
- simple-date-formatter-util-11@1.0.0
- simple-date-formatter-util-10@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.