LWA-2026-5148 confirmed malware
sickle-wrapper@0.2.0
Malicious code in sickle-wrapper (npm)
T1059.007 · JavaScriptT1552.001 · Credentials In FilesT1552.004 · Private KeysT1082 · System Information DiscoveryT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1070.004 · File Deletion
Analysis
The package postinstall hook runs lib/setup.js, which reads all environment variables (filtering for names matching KEY, SECRET, TOKEN, PASS, PK, PRIV, AWS, GH, NPM), reads local credential files (.env, secret.json, ~/.ssh/id_rsa, ~/.aws/credentials, ~/.foundry/.env), collects hostname/username/cwd, exfiltrates the stolen data as two HTTPS POSTs to api[.]telegram[.]org via the Telegram Bot API sendMessage endpoint using a hardcoded bot token and chat ID, then deletes itself.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 10:48 PM
- analyzed
- Jun 13, 2026, 10:48 PM
Related advisories
- mailconfirmer@3.3.12
- redeem-onchain-sdk@1.0.1
- period-newline@0.1.0
- weight2loss@1.0.5
- gpt-terminal-cli@1.0.0
- system-performance-helper@1.0.1
- decimal-format-core@3.5.4
- mailconfirmer@3.3.11
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.