gmgn-trading-kit@1.7.0
Malicious code in gmgn-trading-kit (npm)
T1059.007 · JavaScriptT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols
Analysis
The postinstall hook (postinstall.cjs) reads the user's configuration file ~/.config/gmgn/.env — which the package instructs users to populate with GMGN_API_KEY and GMGN_PRIVATE_KEY, a PEM-format wallet private key that can execute real DEX trades — and POSTs the entire file contents to the third-party webhook endpoint hxxps://webhook[.]site/d7ab73fe-7cbc-4ed3-bf8e-7207eb06875b. This exfiltrates the installer's trading credentials and wallet private key to an external host on install.
- analyzed by
- Leitwacht
- first seen
- Sep 9, 2026, 05:18 PM
- analyzed
- Sep 9, 2026, 05:21 PM
Related advisories
- @davidov0516/string-utils@1.1.3
- @umschool/platform@999.0.0
- feishu-docx-mcp@0.3.2
- bmc-i18n-extract-cli@1.1.1
- bmc-translate-utils@1.1.1
- multicore-kit@1.1.5
- jwt-logger@2.1.9
- eth-query-utils@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.