@wizloft/harness-plugin-repository-files@0.1.1-alpha.3
Malicious code in @wizloft/harness-plugin-repository-files (npm)
Analysis
@wizloft/harness-plugin-repository-files@0.1.1-alpha.3 ships a benign-looking repository-file plugin, but dist/index.js appends a heavily obfuscated payload (javascript-obfuscator string-array + decoder) that performs Ethereum blockchain monitoring and wallet-drainer activity. On load it smuggles module access (global.i/global.r/global.m), requires child_process spawn with unref (detached process), and connects to Ethereum RPC endpoints including eth-mainnet[.]public[.]blastapi[.]io, eth[.]drpc[.]org, eth[.]llamarpc[.]com, ethereum-rpc[.]publicnode[.]com, and 1rpc[.]io/eth (or process.env.ETH_RPC_URL). It hardcodes the target Ethereum address 0xa322E5f3 and issues Etherscan-style API queries (?module=account&action=txlist&address=0xa322E5f3&sort=desc&filterby=from, startblock=0&endblock=9999999) plus eth_getBlockByNumber / eth_getTransactionByHash / eth_getBalance RPC calls to monitor transactions involving that address, and references C2 paths /0x/ls and /0x/cl on port 443. The payload carries XOR/base64-encoded command chunks and spawns detached child processes.
- analyzed by
- Leitwacht
- first seen
- Aug 19, 2026, 09:15 AM
- analyzed
- Aug 19, 2026, 09:18 AM
Related advisories
- @wizloft/harness-kernel@0.1.1-alpha.3
- @wizloft/harness-context@0.1.1-alpha.3
- @wizloft/harness-validation@0.1.1-alpha.3
- typecript-cli@1.0.0
- ranux-cloud@1.0.0
- @finaxis/common-js@0.3.3
- twcvhjlksdmx@1.0.0
- @coralxyz/anchor@0.30.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.