new-solt@0.0.7
Malicious code in new-solt (npm)
Analysis
new-solt@0.0.7 is a crypto-credential theft implant disguised as a Solana-adjacent package. When required and run (or when npm test is executed), it performs full filesystem scanning across the victim's home directories and mounted drives for cryptocurrency wallet files, including: .env files, Solana id.json keypair files, and files with names matching wallet/key/seed/mnemonic/keystore/phantom/metamask patterns. It also steals shell history (bash, zsh, fish, PowerShell) to recover previously typed credentials, and exfiltrates the Telegram Desktop tdata session folder (enabling account takeover). All stolen data is uploaded via HTTP multipart POST to hxxps://vercel-backend-rn1xzfazn-djbdhdfjjt5-2167s-projects[.]vercel[.]app/api/v1. The package additionally depends on the known-malicious child_process npm package, providing a secondary attack vector.
- analyzed by
- Leitwacht
- first seen
- Jun 18, 2026, 07:36 PM
- analyzed
- Jun 18, 2026, 07:37 PM
Related advisories
- node-slot@1.0.7
- mjs-eslint-helper@4.0.1
- server-parket@3.8.1
- delta-time-32bb@1.0.0
- stream-read-35cf@1.0.0
- xboxauthwrapper@3.9.8
- check-ulid@3.0.2
- web3-core-utils@4.3.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.