LWA-2026-10969 confirmed malware

@openzeppelin-5/contracts@1.0.0

Malicious code in @openzeppelin-5/contracts (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1552.004 · Private KeysT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package's preinstall and postinstall hooks run `node index.js`, which harvests the installer's environment variables matching credential patterns (KEY/TOKEN/SECRET/PASS/PRIVATE/MNEMONIC/AWS/GITHUB/NPM/KUBE/VAULT/WALLET/API and similar), reads credential and wallet files from the home directory (.aws/credentials, .ssh/id_rsa, .ssh/id_ed25519, .kube/config, .docker/config.json, .netrc, .pgpass, .npmrc, .git-credentials, gcloud application-default credentials, Solana/Anchor/Sui wallet keystores, Foundry keystores), reads .env/.env.local/.env.production/.env.development/secrets.env from the working directory, and POSTs the entire collected bundle as JSON to hxxps://webhook[.]site/326b0891-2093-4800-a4c1-686ce3e07b09. The hook swallows all errors so the install never fails. This exfiltrates the victim's cloud tokens, CI credentials, and cryptocurrency wallet keys.

analyzed by
Leitwacht
first seen
Aug 11, 2026, 09:10 AM
analyzed
Aug 11, 2026, 09:11 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.