wallet-sdk-9@3.7.73
Malicious code in wallet-sdk-9 (npm)
Analysis
TRUE POSITIVE: wallet-sdk-9@3.7.73 is a crypto-wallet credential stealer. The postinstall script runs index.js which: (1) detects sandbox/CI environments to evade analysis, (2) scans for 19+ targeted files including Solana/Ethereum/Bitcoin/Tron/Sui/Aptos wallet keys, SSH private keys, .env files, mnemonic/seed/recovery phrases, (3) exfiltrates every found file to Telegram via api[.]telegram[.]org/bot<TOKEN>/sendDocument with hardcoded bot token [redacted-credential] and chat ID 6433587894, (4) sends a formatted message with hostname/username. The package name 'wallet-sdk-9' is pretexting — the real wallet SDK names are 'wallet-sdk' with no number. Publisher aicrypto-xzggg / [account] is a throwaway. Static signals confirmed at runtime: postinstall lifecycle + file discovery + Telegram C2 exfil.
- analyzed by
- Leitwacht
- first seen
- Jun 9, 2026, 03:24 AM
- analyzed
- Jun 9, 2026, 03:25 AM
Related advisories
- solana-web3-stable@1.0.0
- solana-rpc-client@1.0.0
- solana-web3-patched@1.0.0
- solana-web3-fixed@1.0.0
- solana-js-client@1.0.0
- solana-web3-fork@1.0.0
- solana-web3-v1@1.0.0
- solana-web3-lts@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.