ecto-nightly-spirit@1.0.6
Malicious code in ecto-nightly-spirit (npm)
Analysis
The package's postinstall.js lifecycle hook runs on installation and harvests a broad range of credentials and secrets from the host. It reads SSH private keys (~/.ssh/id_rsa, id_ed25519, id_ecdsa, config, authorized_keys), cloud-provider credentials (~/.aws/credentials, ~/.azure/accessTokens.json, GCP application_default_credentials.json and credentials.db, ~/.kube/config, /etc/rancher/k3s/k3s.yaml, ~/.docker/config.json, ~/.terraform.d/credentials.tfrc.json, ~/.vault-token), git credentials (~/.git-credentials), browser login/cookie stores (Chrome Login Data and Cookies, Firefox logins.json and key4.db), and cryptocurrency wallets (~/.bitcoin/wallet.dat, ~/.electrum/wallets/default_wallet, ~/.config/solana/id.json). The harvested data is sent to a hardcoded outbound endpoint at IP 154[.]57[.]164[.]70.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 12:09 PM
- analyzed
- Jun 11, 2026, 12:12 PM
Related advisories
- ts-ecro@0.0.6
- farming-tools-12@4.68.54
- wallet-sdk-9@3.7.73
- simple-date-formatter-util-14@1.0.0
- simple-date-formatter-util-13@1.0.0
- simple-date-formatter-util-2@1.0.0
- streak-metrics-math@1.0.1
- json-to-table-util@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.