noon-contracts@1.0.0
Malicious code in noon-contracts (npm)
Analysis
The package's postinstall hook runs "node scripts/setup.js", which after a short setTimeout delay spawns a detached background bash process and performs broad credential and secret theft. It reads all files in ~/.ssh, searches the home tree for .env/.env.* files (max-depth 6) and greps for PRIVATE_KEY/MNEMONIC/SEED_PHRASE/DEPLOYER_WALLET_PRIVATE_KEY, and collects AWS credentials/config plus cli and sso caches (and runs aws sts/s3/lambda/secretsmanager), Kubernetes secrets via "kubectl get secrets -A -o json" and ~/.kube/config, git credentials and ghp_/gho_/glpat- tokens, ~/.docker/config.json plus docker container env, npm/yarn auth tokens, and Vercel/Netlify/Cloudflare/Heroku deploy tokens, plus shell rc/history files. Collected data is exfiltrated as JSON via HTTP POST to the C2 at 82[.]221[.]101[.]203 port 8443 path /t, with an alert-only notification (hostname_user_label) sent to ntfy.sh topic "noon-nc7x4q" using bearer token tk_d8zm1wdv4qd8g7r02gb7giyy6ocme.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 02:11 PM
- analyzed
- Jun 11, 2026, 02:13 PM
Related advisories
- wormgpt-cli@1.0.1
- streak-metrics-math@1.0.1
- streak-metrics-core@1.0.0
- @epsteinlovekids483/crossmint-wallets-sdk-pentest@1.0.0-pentest
- base58-cli@1.0.0
- @wacrot/infra-data-kit@2.1.4
- nodecheck-health@1.0.0
- json-validator-utils@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.