@public-for-cdao/sdk@99.99.99
Malicious code in @public-for-cdao/sdk (npm)
Analysis
A scoped npm package posing as an internal CryptoDAO SDK whose postinstall hook runs a reconnaissance/credential-harvesting script. On installation it collects host and user details, then scrapes a curated list of CI/CD and crypto secrets from environment variables (GitLab CI job/registry/deploy tokens, GitLab access/API tokens, SSH and deploy private keys, AWS access/secret/session keys, database and Redis URLs/passwords, wallet PRIVATE_KEY/MNEMONIC/SEED_PHRASE, Infura/Alchemy API keys, npm/Docker/Harbor credentials). It also reads common .env files (including /home/gitlab-runner/.env and /root/.env), extracts lines containing KEY/SECRET/TOKEN/PASS/PRIVATE/MNEMONIC, and enumerates GitLab-runner build directories. The harvested data is JSON-encoded and exfiltrated over HTTPS to two attacker-controlled collectors (a webhook[.]site bin and a pipedream[.]net endpoint), with TLS verification disabled, and is additionally written to a temp file and printed to stdout. The 99.99.99 version and internal-use naming indicate a dependency-confusion attack targeting private CI/CD pipelines.
- analyzed by
- Leitwacht
- first seen
- Jun 17, 2026, 04:12 AM
- analyzed
- Jun 17, 2026, 04:23 AM
Related advisories
browse all confirmed advisories →Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.