@quantixfinance/contracts@1.0.0
Malicious code in @quantixfinance/contracts (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 Channel
Analysis
The preinstall hook (preinstall.js) harvests the installer's environment variables, collecting any variable whose name contains key, secret, token, pass, mnemonic, seed, wallet, rpc, infura, alchemy, quicknode, ankr, database, api, deploy, contract, vercel, railway, or env, along with the hostname, working directory, and Node version. It POSTs this JSON to host 759017974 on port 61289 at path /0471e9cef36a6718b0f2bfdbec06bd82/47acfe667ff0162697f4af03/54c960d45ce346f9/r. The package ships no actual smart-contract ABI content despite its description.
- analyzed by
- Leitwacht
- first seen
- Sep 3, 2026, 08:43 AM
- analyzed
- Sep 3, 2026, 08:45 AM
Related advisories
- @quantixfinance/database@1.0.1
- @quantixfinance/token@1.0.1
- @quantixfinance/wallet@1.0.0
- @quantixfinance/common@1.0.0
- @quantixfinance/sdk@1.0.0
- @quantixfinance/api@1.0.0
- @quantixfinance/tron@1.0.0
- @quantixfinance/ui@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.