LWA-2026-5625 MAL-2026-10884 ↗ confirmed malware

@public-for-cdao/contracts@99.99.99

Malicious code in @public-for-cdao/contracts (npm)

Analysis

A scoped npm package published at version 99.99.99 (a dependency-confusion lure designed to shadow an internal package of the same name) that runs a credential-harvesting payload from a postinstall hook. On install the payload collects host details (hostname, platform, architecture, username, working directory) and then reads a broad allowlist of CI/CD, cloud, and crypto secrets from environment variables (e.g. CI job/registry tokens, GitLab access tokens, SSH private keys, AWS access/secret/session keys, database and Redis URLs/passwords, NPM tokens, Docker/Harbor credentials, and blockchain PRIVATE_KEY/MNEMONIC/SEED_PHRASE and Infura/Alchemy API keys). It additionally searches common .env file locations and GitLab-runner build directories for lines containing key/secret/token/password/mnemonic material. The harvested data is serialized to JSON and exfiltrated over HTTPS (with TLS verification disabled) to two attacker-controlled collection endpoints, and a copy is written to a temp file. The package has no legitimate functionality.

analyzed by
Leitwacht
first seen
Jun 17, 2026, 04:12 AM
analyzed
Jun 17, 2026, 04:24 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.