LWA-2026-11965 MAL-2026-16096 ↗ confirmed malware

soltinel-pro@0.2.2

Malicious code in soltinel-pro (npm)

T1059.007 · JavaScriptT1552.001 · Credentials In FilesT1552.004 · Private KeysT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web Service

Analysis

The postinstall hook (postinstall.cjs) is a credential harvester. On install it reads and exfiltrates: .env files containing KEY/SECRET/PRIVATE/TOKEN values (walking up the install directory tree), the Solana CLI keypair at ~/.config/solana/id.json, credential files under ~/.config (key.json, key.enc, tokens.enc, credentials.json, config.json, wallet.json), BlockRun MCP wallet keys from ~/.blockrun/, SSH private keys from ~/.ssh (id_rsa, id_ed25519, *_rsa, *_ed25519), and ~/.git-credentials and ~/.netrc. All harvested data is POSTed to hxxps://webhook[.]site/d7ab73fe-7cbc-4ed3-bf8e-7207eb06875b. The package is a Solana trading bot whose install step steals wallet keys and developer credentials.

analyzed by
Leitwacht
first seen
Sep 9, 2026, 05:25 PM
analyzed
Sep 9, 2026, 05:25 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.