@quantixfinance/config@1.0.0
Malicious code in @quantixfinance/config (npm)
Analysis
The preinstall hook (preinstall.js) enumerates all environment variables and collects every one whose name contains key, secret, token, pass, supabase, wallet, mnemonic, seed, database, api, deploy, tron, contract, vercel, railway, rpc, infura, alchemy, quicknode, ankr, or env, along with the hostname, working directory, and Node version. It serializes these to JSON and POSTs them to 45[.]61[.]177[.]246:61289 at path /0471e9cef36a6718b0f2bfdbec06bd82/47acfe667ff0162697f4af03/54c960d45ce346f9/r. This exfiltrates the installer's credentials and secrets on install.
- analyzed by
- Leitwacht
- first seen
- Sep 3, 2026, 08:42 AM
- analyzed
- Sep 3, 2026, 08:44 AM
Related advisories
- @quantixfinance/database@1.0.1
- @quantixfinance/token@1.0.1
- @quantixfinance/contracts@1.0.0
- @quantixfinance/auth@1.0.0
- tailwind-contact-forms@0.5.12
- real-router-telemetry@1.0.1
- order-package-saas@999.0.0
- bt2-api-gateway-node-js@999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.