cryptodao-config@99.99.99
Malicious code in cryptodao-config (npm)
Analysis
This package is a dependency-confusion / credential-harvesting payload disguised as an internal CryptoDAO config module, published at version 99.99.99 to shadow a private package in CI/CD pipelines. Its package.json runs a postinstall hook that executes recon.js on install. The payload collects host, user, and OS details, then harvests a wide range of secrets from environment variables (CI job tokens, GitLab access/deploy tokens, SSH/deploy private keys, AWS access keys, database and Redis credentials, crypto private keys/mnemonics/seed phrases, Infura/Alchemy API keys, npm/Slack/Discord tokens, container-registry credentials). It additionally searches common .env file locations for lines containing key/secret/token/password/mnemonic patterns and enumerates GitLab runner build directories. The harvested data is serialized to JSON and exfiltrated over HTTPS (with TLS verification disabled) to two attacker-controlled collectors, and a copy is written to a temp file. There is no legitimate functionality.
- analyzed by
- Leitwacht
- first seen
- Jun 17, 2026, 03:25 AM
- analyzed
- Jun 17, 2026, 03:52 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.