LWA-2026-11418 confirmed malware

@library-dev-team/data-sanitizer@1.3.0

Malicious code in @library-dev-team/data-sanitizer (npm)

T1552.001 · Credentials In FilesT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

A package named as a "data sanitization utility" is a cryptocurrency wallet-drainer that executes on import. It reads the installer's .env file for PRIVATE_KEY, SECRET, and MNEMONIC values, queries wallet balances over public RPC endpoints, and runs an infinite loop transferring funds to five hardcoded attacker-controlled wallets across Bitcoin, Ethereum, BNB, Solana, Tron, XRP, Cardano, Polkadot, Dogecoin, Litecoin, Cosmos, Algorand, Vechain, Theta, and Filecoin. It cloaks its process as "systemd: [logrotate]", uses randomized delays and camouflage transfers, and pauses for 3 days every 15 days to evade detection. Attacker wallets include 0x70951410C5E9E938D8715288A7229548287a1a62, 0x2B2259cD0B7a4767d7d1caA5D1B15E16438453ba, 0x73D231f43c6952AD320af26605EB097fCE766D93, 0xc530c63C3053455157a82D5175599CdCD5f02587, and 0xB565bfd6Fb4154D50C6Eb1888af52BAFd9fEBD6F.

analyzed by
Leitwacht
first seen
Aug 18, 2026, 02:10 PM
analyzed
Aug 18, 2026, 02:10 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.