coin-fees@20.1.1
Malicious code in coin-fees (npm)
Analysis
coin-fees@20.1.1 is a trojanized package masquerading as an esbuild platform build. Its postinstall hook runs index.js, which waits 30-120 seconds then exfiltrates host information (hostname, platform, architecture, current working directory, package.json), the full process environment, and the user's ~/.npmrc file to the C2 host gvfvq5cm9r9jfs3d6mzp7y8pbkz7[.]oastify[.]com on port 80 via HTTP POST. It also runs whoami, id, uname -a, npm root -g, ver, and tasklist, and scans localhost ports 80/443/3000/5000/8080/8443/9090, reporting open ports. The script suppresses all errors and exits silently when CI/audit environment variables are detected to evade analysis.
- analyzed by
- Leitwacht
- first seen
- Aug 20, 2026, 11:40 PM
- analyzed
- Aug 20, 2026, 11:40 PM
Related advisories
- pump-segments-sdk@20.1.1
- space-items@1.0.0
- runtime-health@1.0.1
- format-helper-lib@1.0.0
- wormgpt-cli@1.0.1
- simple-date-formatter-new-8@1.0.0
- simple-date-formatter-new-6@1.0.0
- simple-date-formatter-new-5@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.