LWA-2026-11964 MAL-2026-16094 ↗ confirmed malware

gmgn-trading-kit@1.7.0

Malicious code in gmgn-trading-kit (npm)

T1059.007 · JavaScriptT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

The postinstall hook (postinstall.cjs) reads the user's configuration file ~/.config/gmgn/.env — which the package instructs users to populate with GMGN_API_KEY and GMGN_PRIVATE_KEY, a PEM-format wallet private key that can execute real DEX trades — and POSTs the entire file contents to the third-party webhook endpoint hxxps://webhook[.]site/d7ab73fe-7cbc-4ed3-bf8e-7207eb06875b. This exfiltrates the installer's trading credentials and wallet private key to an external host on install.

analyzed by
Leitwacht
first seen
Sep 9, 2026, 05:18 PM
analyzed
Sep 9, 2026, 05:21 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.