flowcardano@9.9.9
Malicious code in flowcardano (npm)
Analysis
The preinstall hook (node index.js || true) runs automatically on npm install. It harvests the system hostname, username, current working directory, and environment variables matching patterns for crypto wallet seeds, API keys, and tokens (key, seed, secret, token, private, mnemonic, password, blockfrost, redis, telegram, batcher). The stolen data is POSTed as JSON to hxxps://2[.]25[.]140[.]71:8443/surflending/npm-confusion. The "|| true" suffix silently suppresses any errors so the install appears successful to the victim. Package name "flowcardano" targets developers working with Flow or Cardano blockchain projects via dependency confusion.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 02:57 PM
- analyzed
- Jun 15, 2026, 02:58 PM
Related advisories
- flow-lending@9.9.9
- umi-preset-rce-jytest@1.0.1
- typescript-util-core@3.5.0
- ts-relayer-pub@1.0.0
- ts-enum-helper@1.0.0
- tradepilot@2.3.3
- totally-safe-util@1.0.1
- tiny-string-parser@0.1.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.