LWA-2026-5388 MAL-2026-5808 ↗ confirmed malware

surf-lending@9.9.9

Malicious code in surf-lending (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

Preinstall hook runs index.js which collects the installer's hostname, username, and environment variables matching sensitive patterns (key, seed, secret, token, mnemonic, password, blockfrost, redis, telegram, batcher). The data is JSON-serialised and exfiltrated via HTTPS POST to 2[.]25[.]140[.]71:8443/surflending/npm-confusion. All errors are silently swallowed to avoid detection. The package is a version-squat (9.9.9) designed for dependency confusion.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 02:56 PM
analyzed
Jun 15, 2026, 02:58 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.