LWA-2026-5732 MAL-2026-6335 ↗ confirmed malware

server-parket@3.8.1

Malicious code in server-parket (npm)

T1059.007 · JavaScriptT1083 · File and Directory DiscoveryT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

server-parket@3.8.1 is an information-stealer trojan. On install, the postinstall hook runs a payload that: (1) performs a full recursive filesystem scan (Linux /home, Windows C:-J: drives, macOS /Users) looking for .env files, Solana wallet keys (id.json), and documents containing crypto-wallet keywords (metamask, phantom, keystore, mnemonic, seed, trezor, ledger); (2) collects shell history files (.bash_history, .zsh_history, .fish_history, PowerShell PSReadLine history); (3) on Windows and macOS, locates and archives the Telegram Desktop tdata directory (containing session cookies and authentication data). All harvested data is uploaded via HTTP POST to hxxps://backend-helper-service[.]vercel[.]app/api/v1 using multipart/form-data, batched in 4MB chunks. The C2 endpoint is a Vercel-hosted backend service.

analyzed by
Leitwacht
first seen
Jun 18, 2026, 05:41 PM
analyzed
Jun 18, 2026, 05:43 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.