ve-hemi-rewards@999.0.0
Malicious code in ve-hemi-rewards (npm)
Analysis
This package is a dependency-confusion implant. Its preinstall script (postinstall.js) collects the installer's hostname, username, current working directory, and all environment-variable names matching key/secret/token/pass/private/ssh/deploy/auth/api/rpc/wallet/sentry/docker/graph/slack/host (harvesting credentials, API keys, and tokens from env), then POSTs the stolen data to 185[.]130[.]46[.]35:8443/collect via HTTPS. All errors are silently swallowed (|| true, empty try/catch) so installation succeeds without visible failure. The package ships only 3 files (758 bytes) and uses version 999.0.0 to maximize install priority over legitimate packages in dependency-resolution order.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 02:56 AM
- analyzed
- Jun 15, 2026, 02:58 AM
Related advisories
- token-prices-cron@999.0.0
- hemi-earn-actions@999.0.0
- portal-backend@999.0.0
- thepackagethatworks_@1.0.2
- texttweak-kit@1.0.0
- textdecode@1.2.7
- test-nonmal-pkg-5@1.0.1
- tailwindcss-framer-motion@1.1.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.