wallet-connect-adapter@1.4.2
Malicious code in wallet-connect-adapter (npm)
T1059.007 · JavaScriptT1059.006 · PythonT1105 · Ingress Tool TransferT1027 · Obfuscated Files or InformationT1195.002 · Compromise Software Supply Chain
Analysis
wallet-connect-adapter@1.4.2 is a combosquat of the WalletConnect ecosystem. Its postinstall hook (loader.js) XOR-decodes a base64-encoded Python payload and executes it in a detached background `python -c -` process, first installing the `requests` library via pip if absent. The bundled index.js is a stub with no real functionality. The Python second stage is XOR-obfuscated (32-byte key) so its network behaviour is not visible in the JavaScript stage; the package is a multi-stage dropper that runs attacker-controlled code at install time.
- analyzed by
- Leitwacht
- first seen
- Sep 24, 2026, 03:21 PM
- analyzed
- Sep 24, 2026, 03:23 PM
Related advisories
- sysdo@1.0.0
- core-js-buffer@1.0.0
- @ethers-js/contracts@6.9.0
- n8n-nodes-devops-utils@1.0.0
- txs-runner-lib@1.0.1
- txs-random-lib@1.0.1
- txs-builder@1.0.6
- node-fetch-utils@1.2.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.