LWA-2026-11861 MAL-2026-15851 ↗ confirmed malware

@quantixfinance/contracts@1.0.0

Malicious code in @quantixfinance/contracts (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 Channel

Analysis

The preinstall hook (preinstall.js) harvests the installer's environment variables, collecting any variable whose name contains key, secret, token, pass, mnemonic, seed, wallet, rpc, infura, alchemy, quicknode, ankr, database, api, deploy, contract, vercel, railway, or env, along with the hostname, working directory, and Node version. It POSTs this JSON to host 759017974 on port 61289 at path /0471e9cef36a6718b0f2bfdbec06bd82/47acfe667ff0162697f4af03/54c960d45ce346f9/r. The package ships no actual smart-contract ABI content despite its description.

analyzed by
Leitwacht
first seen
Sep 3, 2026, 08:43 AM
analyzed
Sep 3, 2026, 08:45 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.