LWA-2026-5796 MAL-2026-6318 ↗ confirmed malware

ts-bn-lint-helper@3.1.19

Malicious code in ts-bn-lint-helper (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package is an information-stealer that searches the working directory for credential and wallet files — specifically id.json (Solana CLI wallet keypair), config.toml, Config.toml, config.json, env, and .env — reads them, and POSTs them to hxxps://data-stream[.]space/api/v1 as binary attachments. It also collects the victim's shell history from ~/.bash_history, ~/.zsh_history, ~/.fish_history, ~/.sh_history, and PowerShell PSReadLine history, and exfiltrates those too. Each upload is prefixed with the system USER and local IP address for victim identification. The exfiltration endpoint is data-stream[.]space (HTTPS).

analyzed by
Leitwacht
first seen
Jun 20, 2026, 11:40 AM
analyzed
Jun 20, 2026, 11:41 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.