sea-bound-siren@99.0.1
Malicious code in sea-bound-siren (npm)
Analysis
A credential-harvesting implant. The postinstall hook runs node postinstall.js, which executes grep across the system to steal SSH keys, AWS/GCP/Azure credentials, Docker config, K8s config, .npmrc, .git-credentials, crypto wallets (Electrum, Solana, Bitcoin), browser cookies/logins (Chrome, Firefox), and dumps all environment variables (including NPM_TOKEN, GITHUB_TOKEN, CI tokens, AWS keys, and API keys). The harvested data is base64-encoded and exfiltrated via PUT requests to 154[.]57[.]164[.]64:32271/api/modules/{ECT-472839,ECT-839201}.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 11:33 AM
- analyzed
- Jun 12, 2026, 11:34 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.