LWA-2026-5385 MAL-2026-5806 ↗ confirmed malware

flowdefi@9.9.9

Malicious code in flowdefi (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

flowdefi@9.9.9 is a dependency-confusion credential harvester. Its preinstall hook runs index.js, which collects the hostname, username, working directory, and ALL environment variables matching patterns for crypto wallet mnemonics (seed, mnemonic, private), API keys (key, secret, token), cloud credentials, Telegram bot tokens, and Cardano blockfrost keys, then exfiltrates them via HTTPS POST to 2[.]25[.]140[.]71:8443/surflending/npm-confusion. The package has no legitimate functionality — it contains only the exfil payload and claims to be "flowdefi SDK" despite being 865 bytes. All errors are silently swallowed to avoid detection during install.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 02:57 PM
analyzed
Jun 15, 2026, 02:58 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.