farming-tools-12@4.68.54
Malicious code in farming-tools-12 (npm)
T1059 · Command and Scripting InterpreterT1059.007 · JavaScriptT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web ServiceT1497 · Virtualization/Sandbox Evasion
Analysis
Crypto wallet infostealer. src/index.js contains Telegram-bot exfiltration (bot token [redacted-credential], chat 6433587894) of Solana/Ethereum/Bitcoin/Tron/Sui/Aptos wallets, SSH keys, .env files, mnemonic/seed phrases. Anti-analysis isTestEnvironment() evades sandbox. Executes via postinstall hook -> node scripts/postinstall.js -> require(src/index.js). Delayed setTimeout(7434ms) to bypass runtime detection.
- analyzed by
- Leitwacht
- first seen
- Jun 9, 2026, 03:57 AM
- analyzed
- Jun 9, 2026, 03:58 AM
Related advisories
- os-ulid-void@3.0.2
- wallet-sdk-9@3.7.73
- solana-web3-stable@1.0.0
- solana-rpc-client@1.0.0
- solana-web3-patched@1.0.0
- solana-web3-fixed@1.0.0
- solana-js-client@1.0.0
- solana-web3-fork@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.