bt2-api-gateway-node-js@999.0.0
Malicious code in bt2-api-gateway-node-js (npm)
Analysis
The postinstall hook runs index.js, which after a short delay harvests the installer's credentials and exfiltrates them. It reads ~/.npmrc, ~/.yarnrc, ~/.git-credentials, SSH private keys, AWS credentials and SSO cache, GCP application_default_credentials.json, Azure accessTokens.json, Anthropic/OpenAI/DeepSeek/HuggingFace/Replicate/Cohere/Gemini API keys, k8s config, docker config.json, terraform credentials, GitHub CLI hosts.yml, .netrc, Vercel/Netlify/Supabase/Firebase tokens, database password files, and every environment variable whose name contains TOKEN/KEY/SECRET/PASSWORD/API/AUTH/CREDENTIAL. The collected data is base64-encoded and POSTed to a Telegram bot (api[.]telegram[.]org, chat 8814152665) and to hxxp://2[.]26[.]82[.]63:8888/collect. The package exports only a stub API module and contains no real gateway functionality.
- analyzed by
- Leitwacht
- first seen
- Sep 1, 2026, 04:41 PM
- analyzed
- Sep 1, 2026, 04:42 PM
Related advisories
- cminhouse-api-gateway-nodejs@999.0.0
- space-items@1.0.0
- autbank-core@99.0.0
- @openzeppelin-5/contracts@1.0.0
- @openzeppelin-4/contracts@1.0.0
- permit2@1.0.0
- ethereum-vault-connector@1.0.0
- boring-vault@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.