LWA-2026-10953 confirmed malware

boring-vault@1.0.0

Malicious code in boring-vault (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1552.004 · Private KeysT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

The preinstall and postinstall hooks both run index.js, which harvests the installer's credentials and posts them to a remote endpoint. On install it scans every environment variable whose name matches KEY, TOKEN, SECRET, PASS, PRIVATE, MNEMONIC, RPC, AWS, GITHUB, NPM, KUBE, VAULT, AUTH, PGP, GPG, SEED or WALLET and captures their values; reads ~/.npmrc and ~/.gitconfig; and lists the contents of ~/.ssh, ~/.foundry/keystores, ~/.config/hardhat and ~/.config/gcloud. All of this (hostname, username, cwd, env secrets, npm/git config, wallet keystore and cloud credential directory listings) is POSTed as JSON to hxxps://webhook[.]site/326b0891-2093-4800-a4c1-686ce3e07b09. The hook swallows all errors so installs never fail. The package name mirrors the Boring Vault DeFi protocol and the payload specifically targets crypto wallet keystores and cloud/SSH credentials.

analyzed by
Leitwacht
first seen
Aug 11, 2026, 06:08 AM
analyzed
Aug 11, 2026, 06:08 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.