@wizloft/harness-kernel@0.1.1-alpha.3
Malicious code in @wizloft/harness-kernel (npm)
Analysis
@wizloft/harness-kernel ships an obfuscated crypto-drainer payload in dist/index.js, appended after the package's legitimate exports. On load it installs global backdoor hooks (global.r=require, global.m=module), spawns child processes, and connects to Ethereum RPC endpoints (eth[.]drpc[.]org, eth-mainnet[.]public[.]blastapi[.]io, 1rpc[.]io/eth, ethereum-rpc[.]publicnode[.]com, or the ETH_RPC_URL env var) to monitor the victim's transactions via eth_getBlockByNumber, eth_getTransactionByHash, eth_getBalance, eth_getTransactionCount and eth_call. It queries block-explorer APIs (?module=ac, on=txlist&, address=, ort=desc&f, ilterby=fr, ut[.]com/api) and reports to C2 endpoints hxxps://1re[.]com/0x/ls and hxxps://1re[.]com/0x/cl, draining funds to wallet 0xa322E5f3. HTTP requests use a spoofed Chrome user-agent.
- analyzed by
- Leitwacht
- first seen
- Aug 19, 2026, 09:15 AM
- analyzed
- Aug 19, 2026, 09:21 AM
Related advisories
- @wizloft/harness-context@0.1.1-alpha.3
- @wizloft/harness-validation@0.1.1-alpha.3
- @wizloft/harness-plugin-repository-files@0.1.1-alpha.3
- @wizloft/harness@0.1.1-alpha.3
- cc-skills-helper@1.0.0
- dolyame-boxy-mobile-bnpl-card-panel@35.3.4
- bnpl-blocks-atom-desktop-bnpl-text@35.2.5
- bigops-products-bnpl@35.2.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.