LWA-2026-4681 MAL-2026-5693 ↗ confirmed malware

sea-bound-siren@99.0.1

Malicious code in sea-bound-siren (npm)

Analysis

A credential-harvesting implant. The postinstall hook runs node postinstall.js, which executes grep across the system to steal SSH keys, AWS/GCP/Azure credentials, Docker config, K8s config, .npmrc, .git-credentials, crypto wallets (Electrum, Solana, Bitcoin), browser cookies/logins (Chrome, Firefox), and dumps all environment variables (including NPM_TOKEN, GITHUB_TOKEN, CI tokens, AWS keys, and API keys). The harvested data is base64-encoded and exfiltrated via PUT requests to 154[.]57[.]164[.]64:32271/api/modules/{ECT-472839,ECT-839201}.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 11:33 AM
analyzed
Jun 12, 2026, 11:34 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.