@public-for-cdao/bot@99.99.99
Malicious code in @public-for-cdao/bot (npm)
Analysis
On installation the package runs a postinstall script that performs credential reconnaissance and exfiltration. It collects host details (hostname, OS, architecture, username, working directory) and reads a wide set of environment variables targeting CI/CD and cryptocurrency secrets, including GitLab job/registry/deploy tokens and passwords, GitLab API access tokens, SSH/deploy private keys, AWS access keys and session tokens, database and Redis URLs and passwords, wallet private keys, mnemonics and seed phrases, Infura/Alchemy API keys, Docker, npm, Slack and Discord tokens, blockchain RPC URLs, and container-registry credentials. It additionally searches common .env file locations and CI build directories for lines containing keys, secrets, tokens, passwords, private keys or mnemonics. All harvested data is sent over HTTPS (with TLS certificate verification disabled) to two external attacker-controlled collection endpoints and also written to a temporary file on disk. The published version (99.99.99) and public scope are consistent with a dependency-confusion attack against an internal package of the same name.
- analyzed by
- Leitwacht
- first seen
- Jun 17, 2026, 04:12 AM
- analyzed
- Jun 17, 2026, 04:23 AM
Related advisories
browse all confirmed advisories →Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.