LWA-2026-5287 MAL-2026-5784 ↗ confirmed malware

vaults-monitor-cron@999.0.0

Malicious code in vaults-monitor-cron (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552 · Unsecured CredentialsT1041 · Exfiltration Over C2 Channel

Analysis

vaults-monitor-cron@999.0.0 is a dependency-confusion credential harvester. On npm install, the preinstall hook runs postinstall.js, which collects environment variables matching secret/credential patterns (key, token, pass, private, ssh, deploy, auth, api, rpc, wallet, sentry, docker, slack, host) — including NPM_TOKEN, GITHUB_TOKEN, SSH keys, AWS credentials, and wallet secrets — along with hostname, username, and working directory. The collected data is POSTed to hxxps://185[.]130[.]46[.]35:8443/collect. The hook uses "|| true" to mask failures, making installation appear successful. The package has no legitimate functionality (index.js exports an empty object).

analyzed by
Leitwacht
first seen
Jun 15, 2026, 02:55 AM
analyzed
Jun 15, 2026, 02:56 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.