LWA-2026-11530 MAL-2026-14330 ↗ confirmed malware

@pablo_clueless/sniffr@0.1.1

Malicious code in @pablo_clueless/sniffr (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1027 · Obfuscated Files or Information

Analysis

@pablo_clueless/sniffr@0.1.1 is a trojanized API-schema-diffing dev tool whose main entry (dist/index.js) appends an obfuscated payload that executes on import. The payload spawns detached child processes, builds an Ethereum JSON-RPC client against public RPC endpoints (1rpc[.]io/eth, h-mainnet[.]drpc[.]org, publicnode, ethereum-rpc[.]com, stapi[.]io, or the ETHEREUM_RPC_URL env var), and continuously scans blocks via eth_getBlockByNumber / eth_getTransactionByHash / eth_blockNumber for transactions to the address 0xa322E5f3. Matching transactions are POSTed to C2 endpoints at :443/0x/ls and :443/0x/cl with x-payload- headers. This is a crypto wallet-drainer / transaction-frontrunning monitor concealed inside a benign-looking package.

analyzed by
Leitwacht
first seen
Aug 20, 2026, 05:30 PM
analyzed
Aug 20, 2026, 05:33 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.