LWA-2026-3392 MAL-2026-5360 ↗ confirmed malware

wallet-sdk-9@3.7.73

Malicious code in wallet-sdk-9 (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1552.004 · Private KeysT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1497 · Virtualization/Sandbox Evasion

Analysis

TRUE POSITIVE: wallet-sdk-9@3.7.73 is a crypto-wallet credential stealer. The postinstall script runs index.js which: (1) detects sandbox/CI environments to evade analysis, (2) scans for 19+ targeted files including Solana/Ethereum/Bitcoin/Tron/Sui/Aptos wallet keys, SSH private keys, .env files, mnemonic/seed/recovery phrases, (3) exfiltrates every found file to Telegram via api[.]telegram[.]org/bot<TOKEN>/sendDocument with hardcoded bot token [redacted-credential] and chat ID 6433587894, (4) sends a formatted message with hostname/username. The package name 'wallet-sdk-9' is pretexting — the real wallet SDK names are 'wallet-sdk' with no number. Publisher aicrypto-xzggg / [account] is a throwaway. Static signals confirmed at runtime: postinstall lifecycle + file discovery + Telegram C2 exfil.

analyzed by
Leitwacht
first seen
Jun 9, 2026, 03:24 AM
analyzed
Jun 9, 2026, 03:25 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.