LWA-2026-11503 MAL-2026-14290 ↗ confirmed malware

anhn-cli@1.1.4

Malicious code in anhn-cli (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1102 · Web ServiceT1041 · Exfiltration Over C2 ChannelT1552.001 · Credentials In Files

Analysis

anhn-cli@1.1.4 ships an obfuscated crypto wallet drainer appended to bin/install/install.js. The payload builds an HTTP/HTTPS RPC client that queries Ethereum endpoints (h[.]drpc[.]org, h-mainnet[.]pc[.]io, stapi[.]io, 1r...ut[.]com/api, et...e[.]com, plus the ETH_RPC_URL env var) for the attacker-controlled address 0xa322E5f3, issuing eth_blockNumber, eth_getTransactionCount, eth_getBalance, eth_getBlockByNumber and eth_getTransactionByBlockNumberAndIndex calls, and enumerating transactions via block-explorer API query strings (?module=ac, on=txlist&, filterby=fr, ort=desc&f, ck=9999999). It also references C2 paths :443/0x/ls and :443/0x/cl, sends an x-payload- header, and spawns child processes. The package's other commands (git commit helper, Harvest time-entry, open-site) are benign cover for the injected drainer.

analyzed by
Leitwacht
first seen
Aug 19, 2026, 09:15 AM
analyzed
Aug 19, 2026, 09:19 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.