anhn-cli@1.1.4
Malicious code in anhn-cli (npm)
Analysis
anhn-cli@1.1.4 ships an obfuscated crypto wallet drainer appended to bin/install/install.js. The payload builds an HTTP/HTTPS RPC client that queries Ethereum endpoints (h[.]drpc[.]org, h-mainnet[.]pc[.]io, stapi[.]io, 1r...ut[.]com/api, et...e[.]com, plus the ETH_RPC_URL env var) for the attacker-controlled address 0xa322E5f3, issuing eth_blockNumber, eth_getTransactionCount, eth_getBalance, eth_getBlockByNumber and eth_getTransactionByBlockNumberAndIndex calls, and enumerating transactions via block-explorer API query strings (?module=ac, on=txlist&, filterby=fr, ort=desc&f, ck=9999999). It also references C2 paths :443/0x/ls and :443/0x/cl, sends an x-payload- header, and spawns child processes. The package's other commands (git commit helper, Harvest time-entry, open-site) are benign cover for the injected drainer.
- analyzed by
- Leitwacht
- first seen
- Aug 19, 2026, 09:15 AM
- analyzed
- Aug 19, 2026, 09:19 AM
Related advisories
- pump-segments-sdk@20.1.1
- @library-dev-team/data-sanitizer@1.3.0
- space-items@1.0.0
- leb128x@1.0.1
- core-tailwindcss-utility@3.7.1
- runtime-health@1.0.1
- @evial/runtime-health@1.0.0
- @evial/init-helper-djkwt@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.