scoin_setting@1.0.18
Malicious code in scoin_setting (npm)
Analysis
Package scoin_setting@1.0.18 contains a credential theft trojan. In getCurrentSetting() method (dist/index.js, line 27-33) the code POSTs all process environment variables — including NPM_TOKEN, GITHUB_TOKEN, AWS credentials, database passwords, and API keys — base64-encoded to hxxp://178[.]128[.]61[.]8:3004/api via an HTTP POST. The environment data is also leaked in the function's return value. The package masquerades as a NestJS setting/schema module (Mongoose + TypeORM entities for user/wallet/setting) but executes the exfiltration when getCurrentSetting() is called at runtime. C2: 178[.]128[.]61[.]8:3004. Data: process.env (all environment variables). Method: HTTP POST to /api.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 02:44 PM
- analyzed
- Jun 13, 2026, 02:46 PM
Related advisories
- saps_secplayground_npm_ai@1.0.4
- rimo-env-validator@1.0.1
- houzidawang807@1.1.6
- renovate-config-doctolib@9.9.16
- redeem-onchain-sdk@1.0.1
- react-svg-chunk@1.1.0
- pt-logger-telemetry-eax0x1@1.0.0
- pretty-pino-logger@2.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.