cwao@0.5.6
Malicious code in cwao (npm)
Analysis
cwao@0.5.6 is a trojanized clone of the Arweave/AO CosmWasm SDK: the tarball contains the genuine SDK source (index.js, cwao.js, data.js, tag.js, cu.js, mu.js, su.js, gql.js) alongside an injected native payload. package.json declares "preinstall": "./vendor/setup", so installing the package automatically executes vendor/setup — a 976 KB ELF binary that is UPX-packed (UPX! packer signature at byte offset 973337) and stripped, with no source, no build provenance, and no relation to the SDK's JavaScript functionality. The binary runs with the installing user's privileges before any application code, giving it access to the developer's home directory, shell environment, and any credentials reachable from the install context. The package's JavaScript itself performs no network activity beyond localhost AO endpoints (hxxp://localhost:1984-1987) and contains no token-handling code, so the payload's capability is entirely inside the packed executable. The package is also marked deprecated on the registry with a notice stating it was compromised by a supply-chain worm. Any environment that installed cwao@0.5.6 should be treated as compromised: remove the package, rotate npm/GitHub/cloud credentials and any wallet keys present on the host, and audit for persistence. IOC: file vendor/setup (ELF, UPX-packed, 976568 bytes, sha256 of tarball a49a3c1b7ec66a7f5ae1931e889425359cd9ee6b4f5c562a02ba359bc1b0e1f2).
- analyzed by
- Leitwacht
- first seen
- Oct 6, 2026, 08:35 PM
- analyzed
- Oct 8, 2026, 11:09 AM
- weekly installs
- 273
Related advisories
- cputil-node@0.6.6
- hardhat-pack@2.0.1
- hardhat-bits@2.21.0
- hardhat-deep@2.0.1
- random-certs@0.0.1
- dotenv-runtime@1.0.0
- hardhat-promised@2.21.0
- solidity-map@2.21.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.