@wizloft/harness@0.1.1-alpha.3
Malicious code in @wizloft/harness (npm)
Analysis
@wizloft/harness@0.1.1-alpha.3 is a trojanized npm package: its dist/index.js bundles a legitimate-looking SDK facade with an obfuscated Ethereum wallet-drainer payload that executes on module import. The payload connects to Ethereum RPC endpoints (h[.]drpc[.]org, 1rpc[.]io/eth, public.blockpi, h-mainnet.*, stapi[.]io, and any URL in the ETH_RPC_URL environment variable), issues eth_getBalance / eth_getTransactionCount / eth_blockNumber / eth_getTransactionByNumber calls, queries transaction lists via Etherscan-style API parameters, and sweeps funds from funded wallets to the hardcoded attacker address 0xa322E5f3. It also opens a command channel to C2 paths /0x/ls and /0x/cl on port 443, sends telemetry via _t_u/_t_s parameters and an x-payload- header, and spawns child processes. The code spoofs a Chrome user-agent and uses gzip/brotli decompression and base64 encoding.
- analyzed by
- Leitwacht
- first seen
- Aug 19, 2026, 09:15 AM
- analyzed
- Aug 19, 2026, 09:18 AM
Related advisories
- @wizloft/harness-kernel@0.1.1-alpha.3
- @wizloft/harness-context@0.1.1-alpha.3
- @wizloft/harness-validation@0.1.1-alpha.3
- cc-skills-helper@1.0.0
- dolyame-boxy-mobile-bnpl-card-panel@35.3.4
- bnpl-blocks-atom-desktop-bnpl-text@35.2.5
- bigops-products-bnpl@35.2.9
- devplatform-create-nx-spa@35.4.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.