LWA-2026-5793 MAL-2026-6242 ↗ confirmed malware

atlasora-types@1.0.0

Malicious code in atlasora-types (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1552.004 · Private KeysT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

Package atlasora-types@1.0.0 (combosquatting the AtlasOra Web3 platform) contains a malicious postinstall script (install.js) that harvests credentials and sensitive environment variables. On installation, the script collects OpenAI API keys, AWS credentials, Coinbase API keys, Supabase keys, Revolut API secrets, database URLs, JWT secrets, mnemonic phrases, and any env vars matching patterns like SECRET, TOKEN, PRIVATE_KEY. It reads .env files (including parent directories), ~/.ssh private keys, ~/.npmrc, ~/.aws/credentials, and git config. All collected data is exfiltrated via HTTPS POST to webhook[.]site/22e20640-e2a1-4bb2-b203-061077d055ff. The script silently suppresses errors to avoid disrupting npm install.

analyzed by
Leitwacht
first seen
Jun 20, 2026, 10:56 AM
analyzed
Jun 20, 2026, 10:57 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.