LWA-2026-5622 MAL-2026-10883 ↗ confirmed malware

@public-for-cdao/bot@99.99.99

Malicious code in @public-for-cdao/bot (npm)

Analysis

On installation the package runs a postinstall script that performs credential reconnaissance and exfiltration. It collects host details (hostname, OS, architecture, username, working directory) and reads a wide set of environment variables targeting CI/CD and cryptocurrency secrets, including GitLab job/registry/deploy tokens and passwords, GitLab API access tokens, SSH/deploy private keys, AWS access keys and session tokens, database and Redis URLs and passwords, wallet private keys, mnemonics and seed phrases, Infura/Alchemy API keys, Docker, npm, Slack and Discord tokens, blockchain RPC URLs, and container-registry credentials. It additionally searches common .env file locations and CI build directories for lines containing keys, secrets, tokens, passwords, private keys or mnemonics. All harvested data is sent over HTTPS (with TLS certificate verification disabled) to two external attacker-controlled collection endpoints and also written to a temporary file on disk. The published version (99.99.99) and public scope are consistent with a dependency-confusion attack against an internal package of the same name.

analyzed by
Leitwacht
first seen
Jun 17, 2026, 04:12 AM
analyzed
Jun 17, 2026, 04:23 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.