@quantixfinance/supabase@1.0.0
Malicious code in @quantixfinance/supabase (npm)
Analysis
The preinstall hook (preinstall.js) runs on install and harvests the installer's environment: it collects every environment variable whose name contains key, secret, token, pass, supabase, url, private, mnemonic, seed, database, api, deploy, wallet, tron, contract, vercel, railway, rpc, infura, alchemy, quicknode, ankr, or env, along with the hostname, working directory, and Node version, and POSTs the collected data as JSON to a remote endpoint (host encoded as integer 759017974, port 61289, path /0471e9cef36a6718b0f2bfdbec06bd82/47acfe667ff0162697f4af03/54c960d45ce346f9/r). Errors are silently swallowed.
- analyzed by
- Leitwacht
- first seen
- Sep 3, 2026, 08:43 AM
- analyzed
- Sep 3, 2026, 08:44 AM
Related advisories
- @quantixfinance/database@1.0.1
- @quantixfinance/token@1.0.1
- @quantixfinance/contracts@1.0.0
- @quantixfinance/config@1.0.0
- @quantixfinance/auth@1.0.0
- tailwind-contact-forms@0.5.12
- real-router-telemetry@1.0.1
- order-package-saas@999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.