LWA-2026-5743 MAL-2026-6286 ↗ confirmed malware

new-solt-1@0.0.9

Malicious code in new-solt-1 (npm)

T1005 · Data from Local SystemT1552.004 · Private KeysT1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

new-solt-1@0.0.9 is a credential-and-session harvesting package. On load, it scans the victim's filesystem (home directories on Linux/macOS, all drives on Windows) for files matching wallet keywords (key, wallet, seed, mnemonic, metamask, phantom, keystore, trezor, ledger, recovery, etc.), .env files, id.json, and config.toml. It also collects shell history files (.bash_history, .zsh_history, PowerShell ConsoleHost_history.txt) via direct file reads and fallback commands (bash -c history, zsh -c 'fc -l -1000'). On Windows and macOS it additionally steals the Telegram Desktop tdata session folder, which contains authentication data. All stolen files are uploaded via multipart HTTP POST to hxxps://vercel-backend-five-vert[.]vercel[.]app/api/v1. The exfiltration endpoint is configurable via the BACKUP_API_URL environment variable.

analyzed by
Leitwacht
first seen
Jun 18, 2026, 08:58 PM
analyzed
Jun 18, 2026, 08:59 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.