@quantixfinance/auth@1.0.0
Malicious code in @quantixfinance/auth (npm)
Analysis
The package's preinstall hook (preinstall.js) harvests the installer's environment variables whose names match credential patterns (key, secret, token, password, wallet, mnemonic, seed, database, API, RPC, infura, alchemy, quicknode, ankr, vercel, railway, supabase, deploy, contract, tron), along with the hostname, working directory, and Node version, and POSTs them as a JSON body to a remote host at 45[.]61[.]177[.]246:61289 (path /0471e9cef36a6718b0f2bfdbec06bd82/47acfe667ff0162697f4af03/54c960d45ce346f9/r). The remote host address is encoded as the integer 759017974. This exfiltrates the victim's credentials and secrets at install time.
- analyzed by
- Leitwacht
- first seen
- Sep 3, 2026, 08:42 AM
- analyzed
- Sep 3, 2026, 08:43 AM
Related advisories
- @quantixfinance/database@1.0.1
- @quantixfinance/token@1.0.1
- @quantixfinance/contracts@1.0.0
- tailwind-contact-forms@0.5.12
- real-router-telemetry@1.0.1
- order-package-saas@999.0.0
- bt2-api-gateway-node-js@999.0.0
- cminhouse-api-gateway-nodejs@999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.