atlasora-types@1.0.0
Malicious code in atlasora-types (npm)
Analysis
Package atlasora-types@1.0.0 (combosquatting the AtlasOra Web3 platform) contains a malicious postinstall script (install.js) that harvests credentials and sensitive environment variables. On installation, the script collects OpenAI API keys, AWS credentials, Coinbase API keys, Supabase keys, Revolut API secrets, database URLs, JWT secrets, mnemonic phrases, and any env vars matching patterns like SECRET, TOKEN, PRIVATE_KEY. It reads .env files (including parent directories), ~/.ssh private keys, ~/.npmrc, ~/.aws/credentials, and git config. All collected data is exfiltrated via HTTPS POST to webhook[.]site/22e20640-e2a1-4bb2-b203-061077d055ff. The script silently suppresses errors to avoid disrupting npm install.
- analyzed by
- Leitwacht
- first seen
- Jun 20, 2026, 10:56 AM
- analyzed
- Jun 20, 2026, 10:57 AM
Related advisories
- atlasora-sdk@1.0.0
- atlasora-config@1.0.0
- atlasora-api@1.0.0
- log-taker1@0.1.0
- parket-flow@3.0.1
- ts-big-ecro@3.8.1
- new-solt-1@0.0.9
- color-utils-eee0@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.