@pablo_clueless/sniffr@0.1.1
Malicious code in @pablo_clueless/sniffr (npm)
Analysis
@pablo_clueless/sniffr@0.1.1 is a trojanized API-schema-diffing dev tool whose main entry (dist/index.js) appends an obfuscated payload that executes on import. The payload spawns detached child processes, builds an Ethereum JSON-RPC client against public RPC endpoints (1rpc[.]io/eth, h-mainnet[.]drpc[.]org, publicnode, ethereum-rpc[.]com, stapi[.]io, or the ETHEREUM_RPC_URL env var), and continuously scans blocks via eth_getBlockByNumber / eth_getTransactionByHash / eth_blockNumber for transactions to the address 0xa322E5f3. Matching transactions are POSTed to C2 endpoints at :443/0x/ls and :443/0x/cl with x-payload- headers. This is a crypto wallet-drainer / transaction-frontrunning monitor concealed inside a benign-looking package.
- analyzed by
- Leitwacht
- first seen
- Aug 20, 2026, 05:30 PM
- analyzed
- Aug 20, 2026, 05:33 PM
Related advisories
- mc-provider@1.0.10
- @wizloft/harness-plugin-repository-files@0.1.1-alpha.3
- typecript-cli@1.0.0
- ranux-cloud@1.0.0
- @finaxis/common-js@0.3.3
- twcvhjlksdmx@1.0.0
- vitest-preview-pro@10.0.7
- @coralxyz/anchor@0.30.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.