flow-lending@9.9.9
Malicious code in flow-lending (npm)
Analysis
Package flow-lending@9.9.9 is a credential harvester distributed via version-squat (never-before-published name at version 9.9.9). Its preinstall hook silently runs a script that collects the installer's hostname, username, current working directory, and all environment variables containing key/seed/secret/token/private/mnemonic/password — including API keys, database credentials, cloud tokens, and wallet mnemonics. The harvested data is exfiltrated via HTTPS POST to 2[.]25[.]140[.]71:8443/surflending/npm-confusion. All network errors are silently suppressed so the install appears to succeed with no visible failure.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 02:56 PM
- analyzed
- Jun 15, 2026, 02:57 PM
Related advisories
- umi-preset-rce-jytest@1.0.1
- typescript-util-core@3.5.0
- ts-relayer-pub@1.0.0
- ts-enum-helper@1.0.0
- tradepilot@2.3.3
- totally-safe-util@1.0.1
- tiny-string-parser@0.1.2
- hemi-supply-cron@999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.