LWA-2026-10954 confirmed malware

camelot-ammv2-periphery@1.0.0

Malicious code in camelot-ammv2-periphery (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package's preinstall and postinstall hooks both execute index.js, which harvests the installer's credentials and exfiltrates them. It collects every environment variable whose name matches KEY/TOKEN/SECRET/PASS/PRIVATE/MNEMONIC/RPC/AWS/GITHUB/NPM/KUBE/VAULT/AUTH/PGP/GPG/SEED/WALLET, reads the contents of ~/.npmrc and ~/.gitconfig, and lists the directories ~/.ssh, ~/.foundry/keystores, ~/.config/hardhat, and ~/.config/gcloud, along with hostname, username, cwd, and platform. All collected data is POSTed as JSON to hxxps://webhook[.]site/326b0891-2093-4800-a4c1-686ce3e07b09. The hooks swallow all errors so installation never fails.

analyzed by
Leitwacht
first seen
Aug 11, 2026, 06:08 AM
analyzed
Aug 11, 2026, 06:08 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.