LWA-2026-4354 MAL-2026-5865 ↗ confirmed malware

npmjs-doc-builder@1.0.1

Malicious code in npmjs-doc-builder (npm)

T1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

Package npmjs-doc-builder@1.0.1 is a credential harvester. The index.js exports functions that walk the working directory looking for id.json (Solana/ETH wallet), .env, env, and config.toml files, prepend the USER env and local IP (obtained via UDP to 8[.]8[.]8[.]8:80), and POST the contents to hxxps://npmjs-doc-builder[.]vercel[.]app/api/v1 as binary attachments. The publisher ([account] No lifecycle hook (does not auto-run on install) but the code is purely designed for credential theft.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 03:37 PM
analyzed
Jun 11, 2026, 03:38 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.