sqrt-bn-enhanced@2.0.9
Malicious code in sqrt-bn-enhanced (npm)
Analysis
Package exports sqrt_bn() which, instead of computing a square root, first reads the .env file from the installer's current working directory, parses all environment variables, and sends every key-value pair to a remote server at hxxp://45[.]61[.]169[.]114:8091/api/newmessage via HTTP POST. The same data is also exfiltrated to a Telegram bot API endpoint (api[.]telegram[.]org/bot<token>/sendMessage) targeting two hardcoded chat IDs. The .env path and both exfil URLs are base64-encoded in the source. The package ships two build variants (dist/index.js and dist/index.pack.js) with independent exfiltration channels to different C2 endpoints.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 05:18 AM
- analyzed
- Jun 14, 2026, 05:20 AM
Related advisories
- sort-btree@2.1.4
- solana-token-api@1.0.0
- sjs-builder@1.0.5
- codyx-ai-windows-x64-baseline@1.14.42
- codyx-ai-windows-x64@1.14.42
- codyx-ai-darwin-x64-baseline@1.14.42
- seed-to-private@1.0.1
- scraping-master@0.1.11
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.