cr-bot-common@1.0.0
Malicious code in cr-bot-common (npm)
Analysis
cr-bot-common@1.0.0 ships preinstall and postinstall hooks that harvest secrets and exfiltrate them to a remote host. On install, preinstall.js and postinstall.js collect system information (hostname, platform, user, cwd, node/npm versions), read .env files (including ../.env, /app/.env, /opt/.env), read config/database/wallet/keys/secrets/credentials files, search the home directory and /root,/home,/opt,/app,/var/lib for private-key, wallet, keystore, and mnemonic files, and harvest environment variables whose names match KEY, SECRET, TOKEN, PASSWORD, DATABASE, AWS, PRIVATE, JWT, SESSION, ENCRYPTION, MONGO, POSTGRES, MYSQL, or TON. The collected data is POSTed as JSON to attacker[.]com/collect and attacker[.]com/exfiltrate. The package is presented as a CryptoBot TON wallet integration.
- analyzed by
- Leitwacht
- first seen
- Sep 11, 2026, 09:31 AM
- analyzed
- Sep 11, 2026, 09:32 AM
Related advisories
- soltinel-pro@0.2.2
- @umschool/platform@999.0.0
- order-package-saas@999.0.0
- bt2-api-gateway-node-js@999.0.0
- cminhouse-api-gateway-nodejs@999.0.0
- space-items@1.0.0
- autbank-core@99.0.0
- @openzeppelin-5/contracts@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.