atlasora-utils@1.0.0
Malicious code in atlasora-utils (npm)
Analysis
A trojanized clone posing as a Web3 utility module. On npm install, its postinstall hook (install.js) silently collects environment variables targeting Coinbase/coinbase, OpenAI, Supabase, Revolut, and AWS credentials, plus any env var matching PRIVATE_KEY, MNEMONIC, SECRET, API_KEY, or TOKEN. It also reads .env files (from the cwd and parent directories), ~/.ssh/ private SSH keys, git config, ~/.npmrc, and ~/.aws/credentials. All stolen data is exfiltrated via HTTPS POST to webhook[.]site/22e20640-e2a1-4bb2-b203-061077d055ff. Errors are silently suppressed so the install appears to succeed normally.
- analyzed by
- Leitwacht
- first seen
- Jun 20, 2026, 10:56 AM
- analyzed
- Jun 20, 2026, 10:57 AM
Related advisories
- atlasora-types@1.0.0
- atlasora-sdk@1.0.0
- atlasora-config@1.0.0
- atlasora-api@1.0.0
- log-taker1@0.1.0
- parket-flow@3.0.1
- ts-big-ecro@3.8.1
- new-solt-1@0.0.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.