LWA-2026-11507 confirmed malware

@oss-core-eng/data-formatter@1.0.1

Malicious code in @oss-core-eng/data-formatter (npm)

T1059.007 · JavaScriptT1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1547 · Boot or Logon Autostart Execution

Analysis

@oss-core-eng/data-formatter@1.0.1 is a crypto wallet drainer disguised as a date-formatting utility. On load it reads PRIVATE_KEY/SECRET/MNEMONIC values from the victim's .env file, queries wallet balances over public RPC endpoints (Ethereum/BNB/Polygon/Avalanche via ethers), splits balances into chunks, and in an infinite loop transfers funds to five hardcoded attacker-controlled multi-chain wallets. It masquerades its process title as "systemd: [logrotate]", registers persistence, and uses randomized delays and periodic 3-day pause cycles to evade detection. Attacker wallets include Ethereum 0x70951410C5E9E938D8715288A7229548287a1a62, 0x2B2259cD0B7a4767d7d1caA5D1B15E16438453ba, 0x73D231f43c6952AD320af26605EB097fCE766D93, 0xc530c63C3053455157a82D5175599CdCD5f02587, 0xB565bfd6Fb4154D50C6Eb1888af52BAFd9fEBD6F; Solana 7fxv3Zsr2DKEdZB8erunPq2ZurekwT1Cu2YtS5DwcacU; Bitcoin bc1q4h4a2sjf4k9quhx7xrajfgcsaz082cv5h3g8dt.

analyzed by
Leitwacht
first seen
Aug 19, 2026, 03:45 PM
analyzed
Aug 19, 2026, 03:46 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.