@syncraft-labs/vue@0.4.1
Malicious code in @syncraft-labs/vue (npm)
Analysis
@syncraft-labs/vue@0.4.1 ships an obfuscated wallet-drainer payload in its ESM build (dist/index.js) that executes when the module is imported. The payload queries Ethereum RPC endpoints (eth[.]drpc[.]org, eth-mainnet[.]publicnode[.]com, ethereum-rpc[.]public[.]blastapi[.]io, 1rpc[.]io/eth, api[.]etherscan[.]io) to locate a transaction involving the victim's wallet, then derives a C2 host IP from the victim's transaction recipient-address bytes and fetches XOR-encrypted second-stage payloads from hxxp://<ip>/0x/ls and hxxp://<ip>/0x/cl. The decrypted payload is executed via eval() and also spawned as a detached 'node -e' child process (stdio ignored, windowsHide). A hardcoded attacker-controlled Ethereum address 0xa322E5f3... is embedded as the drain destination. The C2 host is computed from the victim's own address, so it varies per victim.
- analyzed by
- Leitwacht
- first seen
- Aug 22, 2026, 10:46 AM
- analyzed
- Aug 22, 2026, 10:47 AM
- weekly installs
- 143
Related advisories
- @syncraft-labs/react@0.4.1
- @syncraft-labs/core@0.4.1
- @wizloft/harness-kernel@0.1.1-alpha.3
- @wizloft/harness-context@0.1.1-alpha.3
- @wizloft/harness@0.1.1-alpha.3
- cc-skills-helper@1.0.0
- dolyame-boxy-mobile-bnpl-card-panel@35.3.4
- bnpl-blocks-atom-desktop-bnpl-text@35.2.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.