LWA-2026-5761 MAL-2026-6284 ↗ confirmed malware

new-helper@5.8.1

Malicious code in new-helper (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1083 · File and Directory DiscoveryT1552.001 · Credentials In FilesT1555 · Credentials from Password StoresT1005 · Data from Local SystemT1560.002 · Archive Collected DataT1071.001 · Web ProtocolsT1567 · Exfiltration Over Web Service

Analysis

A dependency-confusion package named to impersonate a helper library. On postinstall, it executes a credential and sensitive-data stealer that: (1) scans the home directory and all available drives for wallet files (keystore, mnemonic, seed, Phantom/MetaMask private keys), .env files, id.json, and config.toml; (2) harvests shell history from bash, zsh, fish, sh, and PowerShell; (3) on Windows and macOS, exfiltrates the Telegram Desktop tdata directory (containing session keys for account takeover). All stolen data is uploaded as a multipart POST to hxxps://vercel-backend-five-vert[.]vercel[.]app/api/v1.

analyzed by
Leitwacht
first seen
Jun 19, 2026, 08:53 AM
analyzed
Jun 19, 2026, 08:53 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.