LWA-2026-4308 MAL-2026-3420 ↗ confirmed malware

noon-contracts@1.0.0

Malicious code in noon-contracts (npm)

T1059.007 · JavaScriptT1059.004 · Unix ShellT1543.002 · Systemd ServiceT1543.001 · Launch AgentT1053.003 · CronT1546.004 · Unix Shell Configuration ModificationT1552.001 · Credentials In FilesT1552.004 · Private KeysT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 Channel

Analysis

The package's postinstall hook runs "node scripts/setup.js", which after a short setTimeout delay spawns a detached background bash process and performs broad credential and secret theft. It reads all files in ~/.ssh, searches the home tree for .env/.env.* files (max-depth 6) and greps for PRIVATE_KEY/MNEMONIC/SEED_PHRASE/DEPLOYER_WALLET_PRIVATE_KEY, and collects AWS credentials/config plus cli and sso caches (and runs aws sts/s3/lambda/secretsmanager), Kubernetes secrets via "kubectl get secrets -A -o json" and ~/.kube/config, git credentials and ghp_/gho_/glpat- tokens, ~/.docker/config.json plus docker container env, npm/yarn auth tokens, and Vercel/Netlify/Cloudflare/Heroku deploy tokens, plus shell rc/history files. Collected data is exfiltrated as JSON via HTTP POST to the C2 at 82[.]221[.]101[.]203 port 8443 path /t, with an alert-only notification (hostname_user_label) sent to ntfy.sh topic "noon-nc7x4q" using bearer token tk_d8zm1wdv4qd8g7r02gb7giyy6ocme.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 02:11 PM
analyzed
Jun 11, 2026, 02:13 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.