surf-lending@9.9.9
Malicious code in surf-lending (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols
Analysis
Preinstall hook runs index.js which collects the installer's hostname, username, and environment variables matching sensitive patterns (key, seed, secret, token, mnemonic, password, blockfrost, redis, telegram, batcher). The data is JSON-serialised and exfiltrated via HTTPS POST to 2[.]25[.]140[.]71:8443/surflending/npm-confusion. All errors are silently swallowed to avoid detection. The package is a version-squat (9.9.9) designed for dependency confusion.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 02:56 PM
- analyzed
- Jun 15, 2026, 02:58 PM
Related advisories
- flowdefi@9.9.9
- flowcardano@9.9.9
- flow-lending@9.9.9
- umi-preset-rce-jytest@1.0.1
- typescript-util-core@3.5.0
- ts-relayer-pub@1.0.0
- ts-enum-helper@1.0.0
- tradepilot@2.3.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.