LWA-2026-4282 MAL-2026-5688 ↗ confirmed malware

ecto-nightly-spirit@1.0.6

Malicious code in ecto-nightly-spirit (npm)

T1059.007 · JavaScriptT1083 · File and Directory DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package's postinstall.js lifecycle hook runs on installation and harvests a broad range of credentials and secrets from the host. It reads SSH private keys (~/.ssh/id_rsa, id_ed25519, id_ecdsa, config, authorized_keys), cloud-provider credentials (~/.aws/credentials, ~/.azure/accessTokens.json, GCP application_default_credentials.json and credentials.db, ~/.kube/config, /etc/rancher/k3s/k3s.yaml, ~/.docker/config.json, ~/.terraform.d/credentials.tfrc.json, ~/.vault-token), git credentials (~/.git-credentials), browser login/cookie stores (Chrome Login Data and Cookies, Firefox logins.json and key4.db), and cryptocurrency wallets (~/.bitcoin/wallet.dat, ~/.electrum/wallets/default_wallet, ~/.config/solana/id.json). The harvested data is sent to a hardcoded outbound endpoint at IP 154[.]57[.]164[.]70.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 12:09 PM
analyzed
Jun 11, 2026, 12:12 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.