flowdefi@9.9.9
Malicious code in flowdefi (npm)
Analysis
flowdefi@9.9.9 is a dependency-confusion credential harvester. Its preinstall hook runs index.js, which collects the hostname, username, working directory, and ALL environment variables matching patterns for crypto wallet mnemonics (seed, mnemonic, private), API keys (key, secret, token), cloud credentials, Telegram bot tokens, and Cardano blockfrost keys, then exfiltrates them via HTTPS POST to 2[.]25[.]140[.]71:8443/surflending/npm-confusion. The package has no legitimate functionality — it contains only the exfil payload and claims to be "flowdefi SDK" despite being 865 bytes. All errors are silently swallowed to avoid detection during install.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 02:57 PM
- analyzed
- Jun 15, 2026, 02:58 PM
Related advisories
- flowcardano@9.9.9
- flow-lending@9.9.9
- umi-preset-rce-jytest@1.0.1
- typescript-util-core@3.5.0
- ts-relayer-pub@1.0.0
- ts-enum-helper@1.0.0
- tradepilot@2.3.3
- totally-safe-util@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.