@public-for-cdao/utils@99.99.99
Malicious code in @public-for-cdao/utils (npm)
Analysis
This npm package is a dependency-confusion attack stub. Its package.json registers a postinstall script that executes a bundled recon.js the moment the package is installed. The script collects host details (hostname, OS, architecture, username, working directory) and then harvests a wide range of CI/CD and cloud secrets from environment variables (e.g. CI job/registry/deploy tokens and passwords, GitLab access tokens, SSH private keys, AWS access keys and session tokens, database and Redis URLs/passwords, npm tokens, Slack/Discord tokens, crypto private keys, mnemonics and seed phrases, and container-registry credentials). It additionally searches common .env file locations and CI build directories, extracting any lines that look like keys, secrets, tokens, passwords, or mnemonics. The harvested data is serialized to JSON and exfiltrated over HTTPS (with TLS certificate validation disabled) to two external collector endpoints, and a copy is written to a hidden file in /tmp. The artificially high version number (99.99.99) and public scope are characteristic of a dependency-confusion package designed to override a private internal dependency.
- analyzed by
- Leitwacht
- first seen
- Jun 17, 2026, 04:12 AM
- analyzed
- Jun 17, 2026, 04:23 AM
Related advisories
- @public-for-cdao/providers@1.0.1
- @public-for-cdao/api@99.99.99
- @public-for-cdao/signer@99.99.99
- @public-for-cdao/core@99.99.99
- @public-for-cdao/abi@99.99.99
- cryptodao-sdk@99.99.99
- @mastra/node-speaker@0.1.1
- harpoon-package@1.1.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.