@tonsdk/core@0.9.4
Malicious code in @tonsdk/core (npm)
Analysis
The package declares a postinstall hook (node scripts/postinstall.js) that runs on install under a misleading "Cache validation script" header. After a short random delay, the script fingerprints the host: hostname, username, platform and CPU architecture, base64-encoded in a query string. It sends this to a hardcoded command-and-control server at 213[.]218[.]160[.]189 (ports 8080, then 80, path /s?q=...) over plain HTTP. On Windows it first checks the process list for analysis tools (wireshark, fiddler, procmon, x64dbg, ida) and aborts if any is running. The server response is treated as JavaScript. If it is prefixed with a 64-character hex key, it is XOR-decrypted with that key and base64-decoded. The code is written to a hidden temp file (/tmp/.node_<random>.js, or the user's AppData Local Temp directory on Windows). It is executed by the running Node binary as a detached, unreferenced background process with all stdio ignored, and the file is deleted about five seconds later. This gives the operator arbitrary remote code execution on the installing machine, which survives after the install finishes. The rest of the package (dist/index.js) is a harmless TVM arithmetic helper library that serves as cover.
- analyzed by
- Leitwacht
- first seen
- Oct 6, 2026, 08:18 PM
- analyzed
- Oct 10, 2026, 02:16 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.