LWA-2026-12012 MAL-2026-16137 ↗ confirmed malware

cr-bot-common@1.0.0

Malicious code in cr-bot-common (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1552.004 · Private KeysT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

cr-bot-common@1.0.0 ships preinstall and postinstall hooks that harvest secrets and exfiltrate them to a remote host. On install, preinstall.js and postinstall.js collect system information (hostname, platform, user, cwd, node/npm versions), read .env files (including ../.env, /app/.env, /opt/.env), read config/database/wallet/keys/secrets/credentials files, search the home directory and /root,/home,/opt,/app,/var/lib for private-key, wallet, keystore, and mnemonic files, and harvest environment variables whose names match KEY, SECRET, TOKEN, PASSWORD, DATABASE, AWS, PRIVATE, JWT, SESSION, ENCRYPTION, MONGO, POSTGRES, MYSQL, or TON. The collected data is POSTed as JSON to attacker[.]com/collect and attacker[.]com/exfiltrate. The package is presented as a CryptoBot TON wallet integration.

analyzed by
Leitwacht
first seen
Sep 11, 2026, 09:31 AM
analyzed
Sep 11, 2026, 09:32 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.