@library-dev-team/data-sanitizer@1.3.0
Malicious code in @library-dev-team/data-sanitizer (npm)
Analysis
A package named as a "data sanitization utility" is a cryptocurrency wallet-drainer that executes on import. It reads the installer's .env file for PRIVATE_KEY, SECRET, and MNEMONIC values, queries wallet balances over public RPC endpoints, and runs an infinite loop transferring funds to five hardcoded attacker-controlled wallets across Bitcoin, Ethereum, BNB, Solana, Tron, XRP, Cardano, Polkadot, Dogecoin, Litecoin, Cosmos, Algorand, Vechain, Theta, and Filecoin. It cloaks its process as "systemd: [logrotate]", uses randomized delays and camouflage transfers, and pauses for 3 days every 15 days to evade detection. Attacker wallets include 0x70951410C5E9E938D8715288A7229548287a1a62, 0x2B2259cD0B7a4767d7d1caA5D1B15E16438453ba, 0x73D231f43c6952AD320af26605EB097fCE766D93, 0xc530c63C3053455157a82D5175599CdCD5f02587, and 0xB565bfd6Fb4154D50C6Eb1888af52BAFd9fEBD6F.
- analyzed by
- Leitwacht
- first seen
- Aug 18, 2026, 02:10 PM
- analyzed
- Aug 18, 2026, 02:10 PM
Related advisories
- space-items@1.0.0
- leb128x@1.0.1
- core-tailwindcss-utility@3.7.1
- runtime-health@1.0.1
- @evial/runtime-health@1.0.0
- @evial/init-helper-djkwt@1.0.0
- @evial/runtime-utils@1.0.0
- colorpicker-ui@1.2.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.