soltinel-pro@0.2.2
Malicious code in soltinel-pro (npm)
Analysis
The postinstall hook (postinstall.cjs) is a credential harvester. On install it reads and exfiltrates: .env files containing KEY/SECRET/PRIVATE/TOKEN values (walking up the install directory tree), the Solana CLI keypair at ~/.config/solana/id.json, credential files under ~/.config (key.json, key.enc, tokens.enc, credentials.json, config.json, wallet.json), BlockRun MCP wallet keys from ~/.blockrun/, SSH private keys from ~/.ssh (id_rsa, id_ed25519, *_rsa, *_ed25519), and ~/.git-credentials and ~/.netrc. All harvested data is POSTed to hxxps://webhook[.]site/d7ab73fe-7cbc-4ed3-bf8e-7207eb06875b. The package is a Solana trading bot whose install step steals wallet keys and developer credentials.
- analyzed by
- Leitwacht
- first seen
- Sep 9, 2026, 05:25 PM
- analyzed
- Sep 9, 2026, 05:25 PM
Related advisories
- @umschool/platform@999.0.0
- order-package-saas@999.0.0
- bt2-api-gateway-node-js@999.0.0
- cminhouse-api-gateway-nodejs@999.0.0
- space-items@1.0.0
- autbank-core@99.0.0
- @openzeppelin-5/contracts@1.0.0
- @openzeppelin-4/contracts@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.