LWA-2026-11505 confirmed malware

@oss-core-eng/config-loader@1.0.0

Malicious code in @oss-core-eng/config-loader (npm)

T1552.001 · Credentials In FilesT1059.007 · JavaScriptT1071.001 · Web Protocols

Analysis

The package's main entry point (index.js) is a cryptocurrency wallet drainer that executes on require. It reads private keys and mnemonics from the victim's .env file, queries on-chain balances via public RPC endpoints, and transfers funds in chunks of up to 1500 units to a set of hardcoded attacker-controlled wallets across Bitcoin, Ethereum, BNB, Solana, Tron, Ripple, Cardano, Dogecoin, Polkadot, Cosmos, Algorand, Vechain, Theta, and Filecoin. It runs an infinite loop with randomized delays, a 15-day pause cycle, a 30000 daily transfer limit, and wallet rotation, and it spoofs the process title to "systemd: [logrotate]" to evade detection. Primary receiving Ethereum address: 0x70951410C5E9E938D8715288A7229548287a1a62; additional receiving wallets include 0x2B2259cD0B7a4767d7d1caA5D1B15E16438453ba, 0x73D231f43c6952AD320af26605EB097fCE766D93, 0xc530c63C3053455157a82D5175599CdCD5f02587, and 0xB565bfd6Fb4154D50C6Eb1888af52BAFd9fEBD6F.

analyzed by
Leitwacht
first seen
Aug 19, 2026, 11:00 AM
analyzed
Aug 19, 2026, 11:01 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.