new-helper@5.8.1
Malicious code in new-helper (npm)
Analysis
A dependency-confusion package named to impersonate a helper library. On postinstall, it executes a credential and sensitive-data stealer that: (1) scans the home directory and all available drives for wallet files (keystore, mnemonic, seed, Phantom/MetaMask private keys), .env files, id.json, and config.toml; (2) harvests shell history from bash, zsh, fish, sh, and PowerShell; (3) on Windows and macOS, exfiltrates the Telegram Desktop tdata directory (containing session keys for account takeover). All stolen data is uploaded as a multipart POST to hxxps://vercel-backend-five-vert[.]vercel[.]app/api/v1.
- analyzed by
- Leitwacht
- first seen
- Jun 19, 2026, 08:53 AM
- analyzed
- Jun 19, 2026, 08:53 AM
Related advisories
- hex-type@3.0.2
- streak-kit-map@1.0.0
- streak-calc-math@1.0.0
- streak-metrics-core@1.0.0
- system-performance-helper@1.0.1
- quickbuf@1.0.1
- @wagni_bot/orca-sdk@1.0.0
- atlasora-shared@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.