coral-wraith@1.0.4
Malicious code in coral-wraith (npm)
Analysis
Supply-chain attack package published as "coral-wraith ally module" by user malwguy. The postinstall hook runs node postinstall.js on every install. v1.0.0 unconditionally executes shell commands reading env vars, system files, and HTB flags, then exfiltrates everything via HTTP PUT to 154[.]57[.]164[.]71:30782 (endpoint /api/modules/ECT-472839). At runtime in the sandbox this was confirmed: the egress violation was caught and the HTTP body captured showing all env variables (including API keys, AWS credentials, CI tokens) being siphoned to the attacker IP. v1.0.4 is an evolved version: adds hostname-based gating (/^[0-9a-f]{12}$/) as evasion, same C2 IP plus 127[.]0[.]0[.]1:30782 sibling, weaponizes AWS IMDSv2 metadata service to steal IAM credentials and dump AWS Secrets Manager contents, plus same HTB-flag hunting and file exfil.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 11:46 PM
- analyzed
- Jun 11, 2026, 11:47 PM
Related advisories
- coral-wraith@1.0.0 same package
- internallib_v557@1.0.5
- noon-contracts@1.0.0
- ecto-nightly-spirit@1.0.6
- ts-ecro@0.0.6
- farming-tools-12@4.68.54
- wallet-sdk-9@3.7.73
- simple-date-formatter-util-14@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.