LWA-2026-5631 MAL-2026-10888 ↗ confirmed malware

@public-for-cdao/signer@99.99.99

Malicious code in @public-for-cdao/signer (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

This package is a dependency-confusion attack. Its package.json registers a postinstall hook that runs a bundled recon.js script as soon as the package is installed. The script collects host details (hostname, OS, architecture, username, working directory) and then harvests a broad set of CI/CD and cryptocurrency secrets from environment variables, including CI job tokens, container-registry and deploy credentials, GitLab access tokens, SSH and generic private keys, AWS access/secret/session keys, database and Redis URLs and passwords, npm and Docker registry tokens, and wallet material such as private keys, mnemonics and seed phrases. It additionally searches numerous filesystem paths for .env files (including GitLab-runner and root home directories and production/development variants) and extracts any lines containing key, secret, token, password, private or mnemonic, and enumerates GitLab-runner build directories. The collected data is serialized to JSON and exfiltrated over HTTPS to external collector endpoints (a webhook[.]site bin and a pipedream[.]net endpoint) with TLS certificate validation disabled, and a copy is written to a temp file. The package name and an inflated 99.99.99 version are designed to shadow an internal private package of the same base name.

analyzed by
Leitwacht
first seen
Jun 17, 2026, 04:27 AM
analyzed
Jun 17, 2026, 04:29 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.