LWA-2026-5792 MAL-2026-6241 ↗ confirmed malware

atlasora-shared@1.0.0

Malicious code in atlasora-shared (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1555 · Credentials from Password StoresT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

A trojanized combosquat package impersonating the AtlasOra platform shared utilities. The postinstall hook (install.js) automatically executes on npm install and performs broad credential theft: it harvests environment variables (including OPENAI_API_KEY, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, Coinbase API keys, Supabase credentials, Revolut secrets, database URLs, JWT secrets, wallet mnemonics and private keys), reads .env files from the project and parent directories (upward traversal), and steals SSH private keys, git config, npm config (.npmrc), and AWS credentials (~/.aws/credentials). All collected data is exfiltrated via HTTPS POST to webhook[.]site/22e20640-e2a1-4bb2-b203-061077d055ff. The malware silently swallows all errors to avoid breaking npm install.

analyzed by
Leitwacht
first seen
Jun 20, 2026, 10:56 AM
analyzed
Jun 20, 2026, 10:56 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.