server-parket@3.8.1
Malicious code in server-parket (npm)
Analysis
server-parket@3.8.1 is an information-stealer trojan. On install, the postinstall hook runs a payload that: (1) performs a full recursive filesystem scan (Linux /home, Windows C:-J: drives, macOS /Users) looking for .env files, Solana wallet keys (id.json), and documents containing crypto-wallet keywords (metamask, phantom, keystore, mnemonic, seed, trezor, ledger); (2) collects shell history files (.bash_history, .zsh_history, .fish_history, PowerShell PSReadLine history); (3) on Windows and macOS, locates and archives the Telegram Desktop tdata directory (containing session cookies and authentication data). All harvested data is uploaded via HTTP POST to hxxps://backend-helper-service[.]vercel[.]app/api/v1 using multipart/form-data, batched in 4MB chunks. The C2 endpoint is a Vercel-hosted backend service.
- analyzed by
- Leitwacht
- first seen
- Jun 18, 2026, 05:41 PM
- analyzed
- Jun 18, 2026, 05:43 PM
Related advisories
- parket-helper@0.0.1
- tiny-string-parser@0.1.2
- system-drive@1.0.0
- snavbox@1.0.1
- renovate-config-doctolib@9.9.16
- coral-wraith@1.0.4
- internallib_v557@1.0.5
- noon-contracts@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.