LWA-2026-5148 confirmed malware

sickle-wrapper@0.2.0

Malicious code in sickle-wrapper (npm)

T1059.007 · JavaScriptT1552.001 · Credentials In FilesT1552.004 · Private KeysT1082 · System Information DiscoveryT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1070.004 · File Deletion

Analysis

The package postinstall hook runs lib/setup.js, which reads all environment variables (filtering for names matching KEY, SECRET, TOKEN, PASS, PK, PRIV, AWS, GH, NPM), reads local credential files (.env, secret.json, ~/.ssh/id_rsa, ~/.aws/credentials, ~/.foundry/.env), collects hostname/username/cwd, exfiltrates the stolen data as two HTTPS POSTs to api[.]telegram[.]org via the Telegram Bot API sendMessage endpoint using a hardcoded bot token and chat ID, then deletes itself.

analyzed by
Leitwacht
first seen
Jun 13, 2026, 10:48 PM
analyzed
Jun 13, 2026, 10:48 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.