LWA-2026-11857 MAL-2026-15852 ↗ confirmed malware

@quantixfinance/sdk@1.0.0

Malicious code in @quantixfinance/sdk (npm)

T1059.007 · JavaScriptT1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

The preinstall hook (preinstall.js) runs on install and harvests the environment: it collects every environment variable whose name contains key, secret, token, password, wallet, mnemonic, seed, private, database, API, RPC, or cloud-provider identifiers (Vercel, Railway, Infura, Alchemy, QuickNode, Ankr, Supabase), along with the hostname, working directory, and Node version, and POSTs the assembled JSON to 45[.]61[.]177[.]246:61289 at path /0471e9cef36a6718b0f2bfdbec06bd82/47acfe667ff0162697f4af03/54c960d45ce346f9/r. The remote host is encoded as the decimal integer 759017974 (0x2D3DB1F6). Errors are silently swallowed so the exfiltration is hidden from the installer.

analyzed by
Leitwacht
first seen
Sep 3, 2026, 08:43 AM
analyzed
Sep 3, 2026, 08:44 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.