cminhouse-api-gateway-nodejs@999.0.0
Malicious code in cminhouse-api-gateway-nodejs (npm)
Analysis
The postinstall hook runs index.js, a credential harvester. After a 5-15 second delay (skipping test/CI/container environments), it reads the victim's ~/.npmrc, .yarnrc, .git-credentials, SSH private keys, AWS credentials and SSO cache, GCP application-default credentials, Azure access tokens, kube config, docker config, terraform credentials, GitHub CLI hosts, netlify/supabase/firebase/vercel tokens, .pgpass, .my.cnf, .mongorc.js, vscode settings, gem/pypi/cargo credentials, and every environment variable whose name contains TOKEN/KEY/SECRET/PASSWORD/API/AUTH/CREDENTIAL/ACCESS or provider names (ANTHROPIC, OPENAI, AWS, AZURE, GCP, STRIPE, SLACK, DISCORD, etc.). The collected data is base64-encoded and exfiltrated to a Telegram bot at api[.]telegram[.]org (chat_id 8814152665) via sendMessage/sendDocument, and POSTed to hxxp://2[.]26[.]82[.]63:8888/collect.
- analyzed by
- Leitwacht
- first seen
- Sep 1, 2026, 04:41 PM
- analyzed
- Sep 1, 2026, 04:41 PM
Related advisories
- space-items@1.0.0
- autbank-core@99.0.0
- @openzeppelin-5/contracts@1.0.0
- @openzeppelin-4/contracts@1.0.0
- permit2@1.0.0
- ethereum-vault-connector@1.0.0
- boring-vault@1.0.0
- camelot-ammv2-core@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.