new-solt-1@0.0.9
Malicious code in new-solt-1 (npm)
Analysis
new-solt-1@0.0.9 is a credential-and-session harvesting package. On load, it scans the victim's filesystem (home directories on Linux/macOS, all drives on Windows) for files matching wallet keywords (key, wallet, seed, mnemonic, metamask, phantom, keystore, trezor, ledger, recovery, etc.), .env files, id.json, and config.toml. It also collects shell history files (.bash_history, .zsh_history, PowerShell ConsoleHost_history.txt) via direct file reads and fallback commands (bash -c history, zsh -c 'fc -l -1000'). On Windows and macOS it additionally steals the Telegram Desktop tdata session folder, which contains authentication data. All stolen files are uploaded via multipart HTTP POST to hxxps://vercel-backend-five-vert[.]vercel[.]app/api/v1. The exfiltration endpoint is configurable via the BACKUP_API_URL environment variable.
- analyzed by
- Leitwacht
- first seen
- Jun 18, 2026, 08:58 PM
- analyzed
- Jun 18, 2026, 08:59 PM
Related advisories
- color-utils-eee0@1.0.0
- stream-read-35cf@1.0.0
- hex-conv-ae7a@1.0.0
- buffer-wrap-67d7@1.0.0
- nat-ulid@3.0.2
- xmr-btc-lib-js@1.2.1
- check-ulid@3.0.2
- web3-deploy-helper@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.