solidity-map@2.21.0
Malicious code in solidity-map (npm)
Analysis
solidity-map@2.21.0 is a trojanized clone of the pino logging library. Its README, type definitions and docs are copied verbatim from pino, but the package name, description and author metadata are unrelated to that project, and index.js exports a stub Express middleware rather than pino's API. The real payload is lib/config.js (4.37 MB), a heavily obfuscated javascript-obfuscator bundle using a string-array decoder and \x-escaped constants; it is loaded via require('./lib/config') from index.js, so it executes as soon as the package is imported. On execution it fingerprints the host (hostname, OS, username, platform, timestamp) and beacons it as JSON to hxxp://167[.]88[.]172[.]33:8087/api/log and hxxp://167[.]88[.]172[.]33:8087/api/notify, then uploads a generated sysinfo.txt file via multipart/form-data POST to hxxp://167[.]88[.]172[.]33:8085/upload. Requests carry axios/1.20.0 user agents and custom Userkey/Validation headers. IOCs: C2 167[.]88[.]172[.]33 ports 8085 (/upload) and 8087 (/api/log, /api/notify).
- analyzed by
- Leitwacht
- first seen
- Oct 5, 2026, 07:01 PM
- analyzed
- Oct 5, 2026, 07:01 PM
Related advisories
- sbirontime@1.0.0
- sbman@1.0.0
- bigops-chat-transfer@35.3.6
- tinkoff-statist-browser-typed-client-coretech.statist.mobile.ci@20.1.2
- twork-products-taiga2-products-timeline@20.6.1
- beaver-ui-actions-button@5.4.7
- fdd41@1.0.0
- axios-native@1.16.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.