@quantixfinance/wallet@1.0.0
Malicious code in @quantixfinance/wallet (npm)
T1059.007 · JavaScriptT1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
The preinstall hook (preinstall.js) harvests the installer's environment variables whose names contain key, secret, token, pass, mnemonic, seed, wallet, tron, rpc, infura, alchemy, quicknode, ankr, or similar, along with the hostname, working directory, and Node version, and POSTs them as JSON to 45[.]61[.]177[.]246:61289 at path /0471e9cef36a6718b0f2bfdbec06bd82/47acfe667ff0162697f4af03/54c960d45ce346f9/r. The filter is aimed at crypto-wallet and cloud credentials.
- analyzed by
- Leitwacht
- first seen
- Sep 3, 2026, 08:42 AM
- analyzed
- Sep 3, 2026, 08:44 AM
Related advisories
- @quantixfinance/database@1.0.1
- @quantixfinance/token@1.0.1
- @quantixfinance/contracts@1.0.0
- @quantixfinance/common@1.0.0
- @quantixfinance/sdk@1.0.0
- @quantixfinance/api@1.0.0
- @quantixfinance/tron@1.0.0
- @quantixfinance/ui@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.