LWA-2026-5174 confirmed malware

solana-token-api@1.0.0

Malicious code in solana-token-api (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059.006 · PythonT1027 · Obfuscated Files or InformationT1036.005 · Match Legitimate Resource Name or LocationT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer

Analysis

solana-token-api@1.0.0 is a combosquat package impersonating the Solana ecosystem. The postinstall hook runs an obfuscated JavaScript payload (main.js) that downloads a zip archive from external URLs, extracts it using adm-zip, and executes a Python script (exec.py) via pythonw.exe (Windows headless Python). The payload sets the environment variable REALTEKAUDIO to the C2 endpoint hxxps://postprocesser[.]com/[.]well-known/pki-validation/go/cinnamonroll[.]php?id=mumu before launching the script. The C2 path masquerades as SSL certificate validation traffic. The package includes a benign-looking cover module (solana-token-api.js) that fetches legitimate Solana token metadata, while the actual payload runs in the background during npm install.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 02:47 AM
analyzed
Jun 14, 2026, 02:50 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.