LWA-2026-5794 MAL-2026-6243 ↗ confirmed malware

atlasora-utils@1.0.0

Malicious code in atlasora-utils (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1552.004 · Private KeysT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

A trojanized clone posing as a Web3 utility module. On npm install, its postinstall hook (install.js) silently collects environment variables targeting Coinbase/coinbase, OpenAI, Supabase, Revolut, and AWS credentials, plus any env var matching PRIVATE_KEY, MNEMONIC, SECRET, API_KEY, or TOKEN. It also reads .env files (from the cwd and parent directories), ~/.ssh/ private SSH keys, git config, ~/.npmrc, and ~/.aws/credentials. All stolen data is exfiltrated via HTTPS POST to webhook[.]site/22e20640-e2a1-4bb2-b203-061077d055ff. Errors are silently suppressed so the install appears to succeed normally.

analyzed by
Leitwacht
first seen
Jun 20, 2026, 10:56 AM
analyzed
Jun 20, 2026, 10:57 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.