autbank-core@99.0.0
Malicious code in autbank-core (npm)
Analysis
The preinstall hook (preinstall.js) collects host identity (hostname, platform, architecture, username, home directory, working directory, node version) and harvests environment variables whose names contain KEY, SECRET, TOKEN, PASSWORD, AWS, API, CREDENTIALS, AUTH, or PRIVATE, plus the contents of any .env file and the output of `git remote -v`. It POSTs this data as JSON to 209[.]99[.]185[.]109:8888/npm-exfil, and as a backup encodes the hostname as hex and resolves it as a DNS subdomain of 209[.]99[.]185[.]109. The postinstall hook references a postinstall.js file that is not present in the package.
- analyzed by
- Leitwacht
- first seen
- Aug 14, 2026, 03:06 PM
- analyzed
- Aug 14, 2026, 03:07 PM
Related advisories
- @openzeppelin-5/contracts@1.0.0
- @openzeppelin-4/contracts@1.0.0
- permit2@1.0.0
- ethereum-vault-connector@1.0.0
- boring-vault@1.0.0
- camelot-ammv2-core@1.0.0
- move-bcs-codec@1.0.0
- python-bitcoinlib@1.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.