LWA-2026-3399 MAL-2026-5357 ↗ confirmed malware

farming-tools-12@4.68.54

Malicious code in farming-tools-12 (npm)

T1059 · Command and Scripting InterpreterT1059.007 · JavaScriptT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web ServiceT1497 · Virtualization/Sandbox Evasion

Analysis

Crypto wallet infostealer. src/index.js contains Telegram-bot exfiltration (bot token [redacted-credential], chat 6433587894) of Solana/Ethereum/Bitcoin/Tron/Sui/Aptos wallets, SSH keys, .env files, mnemonic/seed phrases. Anti-analysis isTestEnvironment() evades sandbox. Executes via postinstall hook -> node scripts/postinstall.js -> require(src/index.js). Delayed setTimeout(7434ms) to bypass runtime detection.

analyzed by
Leitwacht
first seen
Jun 9, 2026, 03:57 AM
analyzed
Jun 9, 2026, 03:58 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.