LWA-2026-12278 MAL-2026-16300 ↗ confirmed malware

@baanx/solana-lib@9.9.10

Malicious code in @baanx/solana-lib (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols

Analysis

The package's install hook (node index.js) executes lib/core.js, which collects the host's username, hostname, current working directory and a timestamp, encodes them into a DNS subdomain string prefixed "bxsol." and sends it to the attacker-controlled domain oob[.]algamil7x[.]xyz via a DNS resolve4 lookup. The beacon runs automatically on npm install. The package is presented as a Solana blockchain integration library but performs this hidden network call on install despite its documentation claiming no hidden network calls. The C2 domain is oob[.]algamil7x[.]xyz.

analyzed by
Leitwacht
first seen
Sep 20, 2026, 11:19 AM
analyzed
Sep 20, 2026, 11:20 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.