npmjs-doc-builder@1.0.1
Malicious code in npmjs-doc-builder (npm)
T1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
Package npmjs-doc-builder@1.0.1 is a credential harvester. The index.js exports functions that walk the working directory looking for id.json (Solana/ETH wallet), .env, env, and config.toml files, prepend the USER env and local IP (obtained via UDP to 8[.]8[.]8[.]8:80), and POST the contents to hxxps://npmjs-doc-builder[.]vercel[.]app/api/v1 as binary attachments. The publisher ([account] No lifecycle hook (does not auto-run on install) but the code is purely designed for credential theft.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 03:37 PM
- analyzed
- Jun 11, 2026, 03:38 PM
Related advisories
- npm-bs58.js@2.0.2
- noon-contracts@1.0.0
- ts-eslint-helper@4.0.1
- ts-ecro@0.0.6
- parket-slot@0.0.6
- n8n-nodes-pentest-rce@1.0.1
- mw-filesystem-events-nodream_compat@99.99.99
- motion-lib@2.3.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.