cryptodao-bot@99.99.99
Malicious code in cryptodao-bot (npm)
Analysis
This package is a dependency-confusion payload that executes automatically on installation via a postinstall script (node recon.js). When installed, it harvests reconnaissance and secrets from the host: machine hostname/OS/user, and a broad set of CI/CD and credential environment variables including GitLab CI job/registry/deploy tokens, GitLab access/API tokens, SSH and deploy private keys, AWS access/secret/session keys, database and Redis connection strings and passwords, crypto wallet private keys/mnemonics/seed phrases, Infura/Alchemy API keys, npm auth tokens, Slack/Discord tokens, RPC URLs, and container-registry credentials. It additionally searches common .env file locations (including GitLab-runner and root home directories) and extracts lines containing KEY/SECRET/TOKEN/PASS/PRIVATE/MNEMONIC, and enumerates CI build directories. The gathered data is serialized to JSON and exfiltrated over HTTPS (with TLS verification disabled) to two attacker-controlled collection endpoints (a webhook[.]site bin and a pipedream[.]net endpoint), and is also written to a temp file. The package has no legitimate functionality; index.js is an empty stub. The artificially high 99.99.99 version is characteristic of a dependency-confusion attack designed to override a private internal package of the same name.
- analyzed by
- Leitwacht
- first seen
- Jun 17, 2026, 03:25 AM
- analyzed
- Jun 17, 2026, 03:52 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.