@baanx/solana-lib@9.9.10
Malicious code in @baanx/solana-lib (npm)
Analysis
The package's install hook (node index.js) executes lib/core.js, which collects the host's username, hostname, current working directory and a timestamp, encodes them into a DNS subdomain string prefixed "bxsol." and sends it to the attacker-controlled domain oob[.]algamil7x[.]xyz via a DNS resolve4 lookup. The beacon runs automatically on npm install. The package is presented as a Solana blockchain integration library but performs this hidden network call on install despite its documentation claiming no hidden network calls. The C2 domain is oob[.]algamil7x[.]xyz.
- analyzed by
- Leitwacht
- first seen
- Sep 20, 2026, 11:19 AM
- analyzed
- Sep 20, 2026, 11:20 AM
Related advisories
- @baanx/abis@9.9.9
- @baanx/blockchain-config@9.9.9
- @baanx/domain@9.9.9
- @dbbhk/ui-components@99.0.0
- siriusbeyond@1.0.0
- starbucks-sdk@1.0.0
- action-slack-message-root@1.0.1
- keroeltopkkk@99.99.99
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.