LWA-2026-5740 MAL-2026-6285 ↗ confirmed malware

new-solt@0.0.7

Malicious code in new-solt (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

new-solt@0.0.7 is a crypto-credential theft implant disguised as a Solana-adjacent package. When required and run (or when npm test is executed), it performs full filesystem scanning across the victim's home directories and mounted drives for cryptocurrency wallet files, including: .env files, Solana id.json keypair files, and files with names matching wallet/key/seed/mnemonic/keystore/phantom/metamask patterns. It also steals shell history (bash, zsh, fish, PowerShell) to recover previously typed credentials, and exfiltrates the Telegram Desktop tdata session folder (enabling account takeover). All stolen data is uploaded via HTTP multipart POST to hxxps://vercel-backend-rn1xzfazn-djbdhdfjjt5-2167s-projects[.]vercel[.]app/api/v1. The package additionally depends on the known-malicious child_process npm package, providing a secondary attack vector.

analyzed by
Leitwacht
first seen
Jun 18, 2026, 07:36 PM
analyzed
Jun 18, 2026, 07:37 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.