solana-token-api@1.0.0
Malicious code in solana-token-api (npm)
Analysis
solana-token-api@1.0.0 is a combosquat package impersonating the Solana ecosystem. The postinstall hook runs an obfuscated JavaScript payload (main.js) that downloads a zip archive from external URLs, extracts it using adm-zip, and executes a Python script (exec.py) via pythonw.exe (Windows headless Python). The payload sets the environment variable REALTEKAUDIO to the C2 endpoint hxxps://postprocesser[.]com/[.]well-known/pki-validation/go/cinnamonroll[.]php?id=mumu before launching the script. The C2 path masquerades as SSL certificate validation traffic. The package includes a benign-looking cover module (solana-token-api.js) that fetches legitimate Solana token metadata, while the actual payload runs in the background during npm install.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 02:47 AM
- analyzed
- Jun 14, 2026, 02:50 AM
Related advisories
- pocbitbarrontest@1.0.0
- self-certificate@1.0.0
- meowmeow111@1.0.0
- meowmeow11001@1.0.0
- @ethers-js/contracts@6.9.0
- n8n-nodes-devops-utils@1.0.0
- txs-runner-lib@1.0.1
- txs-random-lib@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.