@quantixfinance/database@1.0.1
Malicious code in @quantixfinance/database (npm)
Analysis
The package's preinstall hook (preinstall.js) harvests the installer's environment variables, collecting every variable whose name contains key, secret, token, pass, supabase, wallet, mnemonic, seed, rpc, infura, alchemy, quicknode, ankr, database, api, deploy, or similar, together with the hostname, working directory, and Node version, and POSTs them as JSON to 45[.]59[.]31[.]6:61289 at path /0471e9cef36a6718b0f2bfdbec06bd82/47acfe667ff0162697f4af03/54c960d45ce346f9/r. The credential filter targeting wallet/mnemonic/seed/RPC-provider keys indicates crypto/DeFi credential theft. The hook suppresses all errors to hide the exfiltration.
- analyzed by
- Leitwacht
- first seen
- Sep 3, 2026, 08:44 AM
- analyzed
- Sep 3, 2026, 08:46 AM
Related advisories
- @quantixfinance/token@1.0.1
- @quantixfinance/contracts@1.0.0
- @quantixfinance/wallet@1.0.0
- @quantixfinance/common@1.0.0
- @quantixfinance/sdk@1.0.0
- @quantixfinance/api@1.0.0
- @quantixfinance/tron@1.0.0
- @quantixfinance/ui@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.